« List of all CVEs

CVE-2013-4351

Published: 10/10/2013 Last updated: 8/6/2024 Reserved: 6/12/2013

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

0install

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (18)