openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2022-34903
Component Overview
Vulnerability Overview
Name
CVE-2022-34903
Source
NVD (
link
)
Debian (
link
)
Description
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
CWEs
CWE-74
Published Date
Jul 1, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2022/07/02/1
Exploit
https://bugs.debian.org/1014157
Issue Tracking
https://dev.gnupg.org/T6027
Issue Tracking
https://security.netapp.com/advisory/ntap-20220826-0005/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5174
Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/06/30/1
Exploit
http://www.openwall.com/lists/oss-security/2022/07/02/1
Exploit
https://bugs.debian.org/1014157
Issue Tracking
https://dev.gnupg.org/T6027
Issue Tracking
https://security.netapp.com/advisory/ntap-20220826-0005/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5174
Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/06/30/1
Exploit
Analysis
#
Affected Component
Analysis
gnupg
Exploitable
Vulnerability Ratings
#
6.5
CVSSv31
5.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
gnupg
buildroot
2025.02.x
1.4.23
Exploitable
gnupg2
buildroot
2025.02.x
2.4.9
Not Affected
gnupg
buildroot
master
1.4.23
Exploitable
gnupg2
buildroot
master
2.5.20
Not Affected
gnupg
openwrt
master
1.4.23-r5
Exploitable
gnupg2
openwrt
master
2.5.20-r1
Not Affected
gnupg
yocto
kirkstone
2.3.7
Not Affected
gnupg
yocto
master
2.5.17
Not Affected
gnupg
yocto
scarthgap
2.4.9
Not Affected