vendor:
GnuPG
by:
Unknown
5.5
CVSS
MEDIUM
Detached signature verification-bypass
347
CWE
Product Name: GnuPG
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2005-3055
CPE: a:gnupg:gnupg
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2006-0580/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2006-0437/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2006-0580/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2006-0437/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2006-0575/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2006-0575/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2006-0579/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2006-0579/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2005-3055/
Platforms Tested:
2005
Detached Signature Verification-Bypass Vulnerability in GnuPG
GnuPG fails to notify scripts when an invalid detached signature is presented, allowing attackers to bypass the signature-verification process.
Mitigation:
Upgrade to a version of GnuPG that has addressed this vulnerability.