CVE-2022-3219

ADVISORY - debian

Summary

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.


EPSS Score: 0.00012 (0.012)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Out-of-bounds Write

ADVISORY - redhat

Out-of-bounds Write


Debian

CREATED

UPDATED

ADVISORY IDCVE-2022-3219
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/gnupg2debdebian12>=2.2.40-1.1Not yet available
debian/gnupg2debdebianunstable>=2.4.7-19Not yet available
debian/gnupg2debdebian13>=2.4.7-17Not yet available
debian/gnupg2debdebian11>=2.2.27-2+deb11u2Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2022-3219
EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3low

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2022-3219
EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

3.3low

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2022-3219
EXPLOITABILITY SCORE

2.5

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.2low

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-qv69-x9jf-vm7x

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY