Use of a broken or risky cryptographic algorithm in GnuPG - CVE-2019-14855

 

Use of a broken or risky cryptographic algorithm in GnuPG - CVE-2019-14855

Published: March 20, 2020 / Updated: July 28, 2020


Vulnerability identifier: #VU31993
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14855
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.


Affected software

GnuPG
DataMosaix Private Cloud
gnupg (Alpine package)
gnupg (Ubuntu package)
gnupg2
gnupg2-debuginfo
gnupg2-debugsource
gnupg2-help
Ubuntu
openEuler

How to mitigate CVE-2019-14855

Install update from vendor's website.

DataMosaix Private Cloud - update to 7.09
gnupg (Alpine package) - addressed in versions 2.2.18-r0, 2.2.19-r0
gnupg (Ubuntu package) - update to 2.2.4-1ubuntu1.3
gnupg2 - update to 2.2.17-5.h1
gnupg2-debuginfo - update to 2.2.17-5.h1
gnupg2-debugsource - update to 2.2.17-5.h1
gnupg2-help - update to 2.2.17-5.h1

External References

Related Security Bulletins