Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-34903

Published: August 31, 2023Last modified: August 31, 2023

Description

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgnupgNot affected (2.2.40-r0)
StreamgnupgNot affected (2.4.3-r1)

References

ON THIS PAGE