GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
References
Link | Resource |
---|---|
https://dev.gnupg.org/T3844 | Issue Tracking Third Party Advisory |
https://usn.ubuntu.com/3675-1/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2018-04-03 17:29
Updated : 2019-02-27 11:37
NVD link : CVE-2018-9234
Mitre link : CVE-2018-9234
JSON object : View
CWE
CWE-320
Key Management Errors
Products Affected
canonical
- ubuntu_linux
gnupg
- gnupg