Total vulnerabilities in the database
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
Software | From | Fixed in |
---|---|---|
gnu / privacy_guard | 1.4.2 | 1.4.2.x |
gnu / privacy_guard | 1.4 | 1.4.x |
gnu / privacy_guard | 1.4.1 | 1.4.1.x |
gnu / privacy_guard | 1.0.3 | 1.0.3.x |
gnu / privacy_guard | 1.2.1 | 1.2.1.x |
gnu / privacy_guard | 1.0.7 | 1.0.7.x |
gnu / privacy_guard | 1.0.5 | 1.0.5.x |
gnu / privacy_guard | 1.0.6 | 1.0.6.x |
gnu / privacy_guard | 1.3.3 | 1.3.3.x |
gnu / privacy_guard | 1.2.2-rc1 | 1.2.2-rc1.x |
gnu / privacy_guard | 1.2.2 | 1.2.2.x |
gnu / privacy_guard | 1.4.2.1 | 1.4.2.1.x |
gnu / privacy_guard | 1.0 | 1.0.x |
gnu / privacy_guard | 1.0.2 | 1.0.2.x |
gnu / privacy_guard | 1.2.3 | 1.2.3.x |
gnu / privacy_guard | 1.2.6 | 1.2.6.x |
gnu / privacy_guard | 1.2.5 | 1.2.5.x |
gnu / privacy_guard | 1.0.4 | 1.0.4.x |
gnu / privacy_guard | 1.3.4 | 1.3.4.x |
gnu / privacy_guard | 1.0.1 | 1.0.1.x |
gnu / privacy_guard | 1.0.3b | 1.0.3b.x |
gnu / privacy_guard | 1.2 | 1.2.x |
gnu / privacy_guard | 1.2.7 | 1.2.7.x |
gnu / privacy_guard | 1.2.4 | 1.2.4.x |