CVE-2019-14855
published 2020-03-20CVE-2019-14855: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.05%
60.3th percentile
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | gnupg1 | < gnupg2 2.2.19-1 (bookworm) | gnupg2 2.2.19-1 (bookworm) |
| debian | gnupg2 | < gnupg2 2.2.19-1 (bookworm) | gnupg2 2.2.19-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnupg | gnupg | < 2.2.18 | 2.2.18 |
| red_hat | gnupg2 | — | — |
| red_hat | gnupg2 | >= 0 < 2.2.19-1 | 2.2.19-1 |
| red_hat | gnupg2 | >= 0 < 2.2.19-1 | 2.2.19-1 |
| red_hat | gnupg2 | >= 0 < 2.2.19-1 | 2.2.19-1 |
| red_hat | gnupg2 | >= 0 < 2.2.19-1 | 2.2.19-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation DataMosaix Private Cloud
cisa_ics·2024-10-10·CVSS 7.5
[HIGH] Rockwell Automation DataMosaix Private Cloud
ICS Advisory
##
Rockwell Automation DataMosaix Private Cloud
Release DateOctober 10, 2024
Alert CodeICSA-24-284-16
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: DataMosaix Private Cloud
- Vulnerabilities: Inadequate Encryption Strength, Out-of-bounds Write, Improper Check for Dropped Privileges, Reliance on Insufficiently Trustworthy Component, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a denial-of-service condition, view user data, or perform remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTE
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2020-09-17
CVE-2019-14855 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to expose sensitive information.
It was discovered that GnuPG signatures could be forged when the SHA-1
algorithm is being used. This update removes validating signatures based on
SHA-1 that were generated after 2019-01-19. In environments where this is
still required, a new option --allow-weak-key-signatures can be used to
revert this behaviour.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnupg2: OpenPGP Key Certification Forgeries with SHA-1
vendor_redhat·2020-01-09·CVSS 7.5
CVE-2019-14855 [HIGH] CWE-326 gnupg2: OpenPGP Key Certification Forgeries with SHA-1
gnupg2: OpenPGP Key Certification Forgeries with SHA-1
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
A flaw was found in OpenPGP Key Certification Forgeries in the way certificate signatures could be forged by using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures.
Statement: This flaw only affects the versions of GnuPG package which defaults to signing with SHA-1. GnuPG 2.0 and above does not use SHA-1 by default therefore are not directly affected by this flaw.
Package: gnupg (Red Hat Enterprise Linux 5) - Out of support scope
Debian
CVE-2019-14855: gnupg1 - A flaw was found in the way certificate signatures could be forged using collisi...
vendor_debian·2019·CVSS 7.5
CVE-2019-14855 [HIGH] CVE-2019-14855: gnupg1 - A flaw was found in the way certificate signatures could be forged using collisi...
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-cpvm-f36g-55vg: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm
ghsa_unreviewed·2022-05-24
CVE-2019-14855 [MEDIUM] CWE-326 GHSA-cpvm-f36g-55vg: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
OSV
CVE-2019-14855: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm
osv·2020-03-20·CVSS 7.5
CVE-2019-14855 [HIGH] CVE-2019-14855: A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-30]
bugzilla·2020-03-20·CVSS 7.5
CVE-2019-14855 [HIGH] CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-30]
CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template t
Bugzilla
CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-31]
bugzilla·2020-03-20·CVSS 7.5
CVE-2019-14855 [HIGH] CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-31]
CVE-2019-14855 gnupg1: gnupg2: OpenPGP Key Certification Forgeries with SHA-1 [fedora-31]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-31.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template t
Bugzilla
CVE-2019-14855 gnupg2: OpenPGP Key Certification Forgeries with SHA-1
bugzilla·2019-11-11·CVSS 7.5
CVE-2019-14855 [HIGH] CVE-2019-14855 gnupg2: OpenPGP Key Certification Forgeries with SHA-1
CVE-2019-14855 gnupg2: OpenPGP Key Certification Forgeries with SHA-1
OpenPGP Key Certification Forgeries with SHA-1. Older versions of OpenPGP implementations will default to using SHA-1 which is not secure.
Discussion:
Acknowledgments:
Name: Werner Koch (GnuPG project)
---
Statement:
This flaw only affects the versions of GnuPG package which defaults to signing with SHA-1. GnuPG 2.0 and above does not use SHA-1 by default therefore are not directly affected by this flaw.
---
External References:
https://rwc.iacr.org/2020/slides/Leurent.pdf
---
Created gnupg1 tracking bugs for this issue:
Affects: fedora-30 [bug 1815379]
Affects: fedora-31 [bug 1815380]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14855https://dev.gnupg.org/T4755https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.htmlhttps://rwc.iacr.org/2020/slides/Leurent.pdfhttps://usn.ubuntu.com/4516-1/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14855https://dev.gnupg.org/T4755https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.htmlhttps://rwc.iacr.org/2020/slides/Leurent.pdfhttps://usn.ubuntu.com/4516-1/
2020-03-20
Published