5

CVE-2006-0049

gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.

Data is provided by the National Vulnerability Database (NVD)
GnuPrivacy Guard Version1.0
GnuPrivacy Guard Version1.0.1
GnuPrivacy Guard Version1.0.2
GnuPrivacy Guard Version1.0.3
GnuPrivacy Guard Version1.0.3b
GnuPrivacy Guard Version1.0.4
GnuPrivacy Guard Version1.0.5
GnuPrivacy Guard Version1.0.6
GnuPrivacy Guard Version1.0.7
GnuPrivacy Guard Version1.2
GnuPrivacy Guard Version1.2.1
GnuPrivacy Guard Version1.2.2
GnuPrivacy Guard Version1.2.2 Updaterc1
GnuPrivacy Guard Version1.2.3
GnuPrivacy Guard Version1.2.4
GnuPrivacy Guard Version1.2.5
GnuPrivacy Guard Version1.2.6
GnuPrivacy Guard Version1.2.7
GnuPrivacy Guard Version1.3.3
GnuPrivacy Guard Version1.3.4
GnuPrivacy Guard Version1.4
GnuPrivacy Guard Version1.4.1
GnuPrivacy Guard Version1.4.2
GnuPrivacy Guard Version1.4.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.48% 0.88
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N