CVE-2022-34903Injection in Gnupg

Severity
6.5MEDIUMNVD
EPSS
1.8%
top 17.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateFeb 15

Description

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 2.2 | Impact: 4.2

Affected Packages1 packages

NVDgnupg/gnupg2.3.6

Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36

Patches

🔴Vulnerability Details

3
GHSA
GHSA-356p-pg27-x2cf: GnuPG through 22022-07-02
CVEList
CVE-2022-34903: GnuPG through 22022-07-01
OSV
CVE-2022-34903: GnuPG through 22022-07-01

📋Vendor Advisories

6
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Ubuntu
GnuPG vulnerability2022-07-12
Microsoft
GnuPG through 2.3.6 in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g. use of GPGME) are met allows signature forgery via 2022-07-12
Ubuntu
GnuPG vulnerability2022-07-05
Red Hat
gpg: Signature spoofing via status line injection2022-06-30