ALT-PU-2025-7346-2
Closed vulnerabilities
Published: 2022-06-10
BDU:2023-03850
Уязвимость функции write_status_text_and_buffer компонента cpr.c программы для шифрования информации и создания электронных цифровых подписей GnuPG, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
Severity: MEDIUM (6.5)
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
References:
Published: 2022-07-02
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2022-34903
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
References:
- [oss-security] 20220702 Re: GnuPG signature spoofing via status line injection
- [oss-security] 20220702 Re: GnuPG signature spoofing via status line injection
- https://bugs.debian.org/1014157
- https://bugs.debian.org/1014157
- https://dev.gnupg.org/T6027
- https://dev.gnupg.org/T6027
- FEDORA-2022-0dbfb7e270
- FEDORA-2022-0dbfb7e270
- FEDORA-2022-aa14d396dd
- FEDORA-2022-aa14d396dd
- FEDORA-2022-1124e5882d
- FEDORA-2022-1124e5882d
- FEDORA-2022-1747eea46c
- FEDORA-2022-1747eea46c
- https://security.netapp.com/advisory/ntap-20220826-0005/
- https://security.netapp.com/advisory/ntap-20220826-0005/
- DSA-5174
- DSA-5174
- https://www.openwall.com/lists/oss-security/2022/06/30/1
- https://www.openwall.com/lists/oss-security/2022/06/30/1