QID 354640
Date Published: 2023-01-02
QID 354640: Amazon Linux Security Advisory for gnupg2 : AL2012-2022-372
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-34903:
2102868: CVE-2022-34903 gpg: Signature spoofing via status line injection
A vulnerability was found in GnuPG. This issue occurs due to an escape detection loop at the write_status_text_and_buffer() function in g10/cpr.c. This flaw allows a malicious actor to bypass access control.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 354640
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2022-372 | Amazon Linux Bare Metal |
|