FS#58120 - [gnupg] CVE-2018-9234: Unenforced configuration allows for apparently valid certifications actually
Attached to Project:
Arch Linux
Opened by Karol Babioch (kbabioch) - Thursday, 05 April 2018, 08:25 GMT
Last edited by Gaetan Bisson (vesath) - Thursday, 05 April 2018, 20:36 GMT
Opened by Karol Babioch (kbabioch) - Thursday, 05 April 2018, 08:25 GMT
Last edited by Gaetan Bisson (vesath) - Thursday, 05 April 2018, 20:36 GMT
|
Details
Description:
GnuPG through version 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. References: https://bugzilla.redhat.com/show_bug.cgi?id=1563930 https://dev.gnupg.org/T3844 https://dev.gnupg.org/rGa17d2d1f690ebe5d005b4589a5fe378b6487c657 |
This task depends upon
Closed by Gaetan Bisson (vesath)
Thursday, 05 April 2018, 20:36 GMT
Reason for closing: Fixed
Additional comments about closing: gnupg-2.2.5-2 in [testing]
Thursday, 05 April 2018, 20:36 GMT
Reason for closing: Fixed
Additional comments about closing: gnupg-2.2.5-2 in [testing]
Levente: Instead of closing, next time, I'll just reassign the ticket to you. I like my list of open tickets to reflect what I have left to do.