mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 01:04:30 +00:00
928 B
928 B
CVE-2006-0049
Description
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.
POC
Reference
- http://securityreason.com/securityalert/450
- http://securityreason.com/securityalert/450
- http://securityreason.com/securityalert/568
- http://securityreason.com/securityalert/568
Github
No PoCs found on GitHub currently.