CVE-2006-0455

Description

gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command gpg --verify.

Risk Information

Base Score
7.4
MODERATE
Vector
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
2.209

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.0Windows
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.0.1Windows
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.0.2Windows
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.0.3Windows
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.0.3bWindows
Multiple Vulnerabilities are affected in GNU Privacy Guard (x64) 1.2.1Windows
Vulnerabilities CVE-2003-0971,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.0.4Windows
Vulnerabilities CVE-2003-0971,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.0.5Windows
Vulnerabilities CVE-2003-0971,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.0.6Windows
Vulnerabilities CVE-2003-0971,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.0.7Windows
Vulnerabilities CVE-2003-0971,CVE-2003-0978,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.2Windows
Vulnerabilities CVE-2003-0971,CVE-2003-0978,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.2.2Windows
Vulnerabilities CVE-2003-0971,CVE-2003-0978,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.2.2-rc1Windows
Vulnerabilities CVE-2003-0971,CVE-2003-0978,CVE-2006-0049,CVE-2006-0455 are affected in GNU Privacy Guard (x64) 1.2.3Windows
Vulnerabilities CVE-2003-0978,CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.3.3Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.5Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.6Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.7Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.3.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.1Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.2Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234