ISOMAN

CVE

CVE-2018-9234

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. https://dev.gnupg.org/T3844
  2. https://usn.ubuntu.com/3675-1/
  3. https://dev.gnupg.org/T3844
  4. https://usn.ubuntu.com/3675-1/