VDB

DEBIAN-CVE-2019-14855

DEBIAN-CVE-2019-14855 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14gnupg20, 0, 0
Debian:12gnupg11.4.23-2, 1.4.23-1.1, 0
Debian:11gnupg11.4.23-2, 0, 1.4.23-1.1
Debian:12gnupg20, 0, 0
Debian:13gnupg20, 0, 0
Debian:13gnupg10, 1.4.23-3, 1.4.23-3
Debian:14gnupg10, 1.4.23-3, 1.4.23-3
Debian:11gnupg20, 0, 0

Timeline

  • Mar 20, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›