Lucene search

K
osvGoogleOSV:USN-4516-1
HistorySep 17, 2020 - 5:41 p.m.

gnupg2 vulnerability

2020-09-1717:41:13
Google
osv.dev
6

7.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.4%

It was discovered that GnuPG signatures could be forged when the SHA-1
algorithm is being used. This update removes validating signatures based on
SHA-1 that were generated after 2019-01-19. In environments where this is
still required, a new option --allow-weak-key-signatures can be used to
revert this behaviour.

7.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.4%