Total vulnerabilities in the database
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".
Software | From | Fixed in |
---|---|---|
gnu / privacy_guard | 1.4.2 | 1.4.2.x |
gnu / privacy_guard | 1.4 | 1.4.x |
gnu / privacy_guard | 1.4.1 | 1.4.1.x |
gnu / privacy_guard | 1.0.3 | 1.0.3.x |
gnu / privacy_guard | 1.2.1 | 1.2.1.x |
gnu / privacy_guard | 1.0.7 | 1.0.7.x |
gnu / privacy_guard | 1.0.5 | 1.0.5.x |
gnu / privacy_guard | 1.0.6 | 1.0.6.x |
gnu / privacy_guard | 1.3.3 | 1.3.3.x |
gnu / privacy_guard | 1.2.2-rc1 | 1.2.2-rc1.x |
gnu / privacy_guard | 1.2.2 | 1.2.2.x |
gnu / privacy_guard | 1.0 | 1.0.x |
gnu / privacy_guard | 1.0.2 | 1.0.2.x |
gnu / privacy_guard | 1.2.3 | 1.2.3.x |
gnu / privacy_guard | 1.2.6 | 1.2.6.x |
gnu / privacy_guard | 1.2.5 | 1.2.5.x |
gnu / privacy_guard | 1.0.4 | 1.0.4.x |
gnu / privacy_guard | 1.3.4 | 1.3.4.x |
gnu / privacy_guard | 1.0.1 | 1.0.1.x |
gnu / privacy_guard | 1.0.3b | 1.0.3b.x |
gnu / privacy_guard | 1.2 | 1.2.x |
gnu / privacy_guard | 1.2.7 | 1.2.7.x |
gnu / privacy_guard | 1.2.4 | 1.2.4.x |