Unrated severityNVD Advisory· Published Apr 4, 2018· Updated Aug 5, 2024
CVE-2018-9234
CVE-2018-9234
Description
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- osv-coords3 versionspkg:rpm/opensuse/gpg2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
< 2.2.27-2.4+ 2 more
- (no CPE)range: < 2.2.27-2.4
- (no CPE)range: < 2.0.24-9.14.1
- (no CPE)range: < 2.0.24-9.14.1
Patches
Vulnerability mechanics
References
2- usn.ubuntu.com/3675-1/mitrevendor-advisoryx_refsource_UBUNTU
- dev.gnupg.org/T3844mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.