gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
| Software | From | Fixed in |
|---|---|---|
| signing-party_project / signing-party | 1.1 | 2.10 |
| debian / debian_linux | 8.0 | 8.0.x |
| opensuse / leap | 42.3 | 42.3.x |
| opensuse / leap | 15.0 | 15.0.x |