VYPR

rpm package

suse/gpg2&distro=SUSE Linux Enterprise Server 12 SP2-BCL

pkg:rpm/suse/gpg2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Vulnerabilities (2)

  • CVE-2022-34903Jul 1, 2022
    affected < 2.0.24-9.11.1fixed 2.0.24-9.11.1

    GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

  • CVE-2018-12020Jun 8, 2018
    affected < 2.0.24-9.3.1fixed 2.0.24-9.3.1

    mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP da