GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
References
Link | Resource |
---|---|
https://dev.gnupg.org/T3844 | Issue Tracking Third Party Advisory |
https://usn.ubuntu.com/3675-1/ | Third Party Advisory |
https://dev.gnupg.org/T3844 | Issue Tracking Third Party Advisory |
https://usn.ubuntu.com/3675-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://dev.gnupg.org/T3844 - Issue Tracking, Third Party Advisory | |
References | () https://usn.ubuntu.com/3675-1/ - Third Party Advisory |
Information
Published : 2018-04-04 00:29
Updated : 2024-11-21 04:15
NVD link : CVE-2018-9234
Mitre link : CVE-2018-9234
CVE.ORG link : CVE-2018-9234
JSON object : View
Products Affected
gnupg
- gnupg
canonical
- ubuntu_linux
CWE
CWE-320
Key Management Errors