CVE-2019-14855 PUBLISHED

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

EPSS 0.40% · 60.7th percentile

Risk Scores

EPSS Score
0.40%
60.7th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSgnupg10, 1.4.23-2, 1.4.23-1.1build4
Ubuntu:25.10gnupg11.4.23-3, 0
Ubuntu:20.04:LTSgnupg11.4.23-1, 0
Ubuntu:Pro:16.04:LTSgnupg1.4.20-1ubuntu3.3+esm2, 1.4.20-1ubuntu3.3+esm3, 1.4.20-1ubuntu3
Ubuntu:18.04:LTSgnupg11.4.22-3ubuntu2, 1.4.22-3ubuntu1, 1.4.22-1ubuntu1
Ubuntu:Pro:14.04:LTSgnupg1.4.16-1ubuntu2.6+esm1, 1.4.14-1ubuntu2, 1.4.15-1.1ubuntu1
Ubuntu:Pro:16.04:LTSgnupg22.0.28-3ubuntu1, 2.1.11-6ubuntu2.1, 2.1.11-6ubuntu2
Ubuntu:18.04:LTSgnupg22.2.4-1ubuntu1.1, 2.2.4-1ubuntu1.2, 2.2.4-1ubuntu1
Ubuntu:22.04:LTSgnupg11.4.23-1.1build1, 0

Timeline

References

Open in Interactive Console →