rpm package
opensuse/gpg2&distro=openSUSE Leap 15.0
pkg:rpm/opensuse/gpg2&distro=openSUSE%20Leap%2015.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-13050 | — | < 2.2.5-lp151.6.3.1 | 2.2.5-lp151.6.3.1 | Jun 29, 2019 | Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent | ||
| CVE-2018-1000858 | — | < 2.2.5-lp150.3.6.1 | 2.2.5-lp150.3.6.1 | Dec 20, 2018 | GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in |
- CVE-2019-13050Jun 29, 2019affected < 2.2.5-lp151.6.3.1fixed 2.2.5-lp151.6.3.1
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent
- CVE-2018-1000858Dec 20, 2018affected < 2.2.5-lp150.3.6.1fixed 2.2.5-lp150.3.6.1
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in