A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
Version | Score | Severity | Vector String |
---|---|---|---|
3.0 | 5.3 | Medium | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Product | Vendor | Version |
---|---|---|
gnupg2 | Red Hat | 6.4.0.13 |