Total vulnerabilities in the database
GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
Software | From | Fixed in |
---|---|---|
gnu / privacy_guard | 1.0.3 | 1.0.3.x |
gnu / privacy_guard | 1.2.1 | 1.2.1.x |
gnu / privacy_guard | 1.0.7 | 1.0.7.x |
gnu / privacy_guard | 1.0.5 | 1.0.5.x |
gnu / privacy_guard | 1.0.6 | 1.0.6.x |
gnu / privacy_guard | 1.2.2-rc1 | 1.2.2-rc1.x |
gnu / privacy_guard | 1.2.2 | 1.2.2.x |
gnu / privacy_guard | 1.0.2 | 1.0.2.x |
gnu / privacy_guard | 1.2.3 | 1.2.3.x |
gnu / privacy_guard | 1.2 | 1.2.x |
gnu / privacy_guard | 1.0.3b | 1.0.3b.x |
gnu / privacy_guard | 1.0.4 | 1.0.4.x |