Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Sec

#23750de 56,327
10CVSS total
Vulnerabilidades · 1
PT-2019-12434
10
2019-04-30
Signing Party · Signing-Party · CVE-2019-11627
**Name of the Vulnerable Software and Affected Versions** signing-party versions 1.1.x through 2.9 **Description** The issue concerns an unsafe shell call in the gpg-key2ps component, which enables shell injection. This can be exploited via a User ID. **Recommendations** For versions 1.1.x through 2.9, consider disabling the gpg-key2ps component until a patch is available. Restrict access to the User ID field to minimize the risk of exploitation.