Related Vulnerabilities: CVE-2022-34903  

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

Description

The MITRE CVE dictionary describes this issue as:

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

Additional Information

  • Bugzilla 2102868: CVE-2022-34903 gpg: Signature spoofing via status line injection
  • CWE-347: Improper Verification of Cryptographic Signature
  • FAQ: Frequently asked questions about CVE-2022-34903