#VU64909 Improper Verification of Cryptographic Signature in GnuPG - CVE-2022-34903
Published: July 4, 2022 / Updated: April 4, 2025
GnuPG
GNU
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to an error in GnuPG, which allows signature spoofing via arbitrary injection into the status line. A remote attacker who controls the secret part of any signing-capable key or subkey in the victim's keyring, can take advantage of this flaw to provide a correctly-formed signature that some software, including gpgme, will accept to have validity and signer fingerprint chosen from the attacker.