VDB

DEBIAN-CVE-2022-3219

DEBIAN-CVE-2022-3219 PUBLISHED CVSS 3.299999952316284 LOW

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

Risk Scores

CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Debian:14gnupg20, 2.4.9-3, 2.4.8-3
Debian:12gnupg22.2.46~pre1-1, 0, 2.2.40-1.1
Debian:13gnupg22.4.8-6, 2.4.9-1, 2.4.9-2
Debian:11gnupg22.4.5-3, 2.4.6-1, 2.4.7-1

Timeline

  • Feb 23, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›