Lucene search

K
f5F5F5:K08654551
HistorySep 09, 2019 - 12:00 a.m.

K08654551 : GnuPG vulnerability CVE-2019-13050

2019-09-0900:00:00
my.f5.com
12

8 High

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.8%

Security Advisory Description

Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack. (CVE-2019-13050)

Impact

Traffix SDC

The system may experience a denial-of-service (DoS) attack when it is importing a compromised certificate from the SKS keyserver network.

BIG-IP, BIG-IQ, Enterprise Manager, and F5 iWorkflow

There is no impact; these F5 products are not affected by this vulnerability.