5
CVSSv2

CVE-2022-24953

Published: 17/02/2022 Updated: 08/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Crypt_GPG extension prior to 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pear crypt gpg

Vendor Advisories

Debian Bug report logs - #1005921 CVE-2022-24953: Crypt_GPG <167 does not prevent additional options in GPG calls Package: src:php-crypt-gpg; Maintainer for src:php-crypt-gpg is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Reported by: Guilhem Moulin <guilhem@debianorg> Date: Thu, 17 Feb 2 ...