vendor:
GnuPG
by:
5.5
CVSS
MEDIUM
Arbitrary Content Injection
94
CWE
Product Name: GnuPG
Affected Version From:
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:gnupg:gnupg
Platforms Tested:
Arbitrary Content Injection in GnuPG
The vulnerability allows an attacker to add arbitrary content into a message without the end user knowing. An attacker can exploit this weakness in applications using GnuPG to add arbitrary content into a signed and/or encrypted message.
Mitigation:
Upgrade to the latest version of GnuPG.