CVE-2019-13050: High severity gnupg 2 (gnu privacy guard) vulnerability
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2019-13050.
What is the severity of CVE-2019-13050?
CVE-2019-13050 has a severity rating of 7.5 (High).
Which software is affected by CVE-2019-13050?
CVE-2019-13050 affects Gnupg, Sks Keyserver Project Sks Keyserver, Fedora, openSUSE Leap, and Apple High Sierra.
How does CVE-2019-13050 pose a risk?
CVE-2019-13050 can cause a persistent denial of service by retrieving data from the SKS keyserver network.
Are there any references for further information?
Yes, you can find more information about CVE-2019-13050 at the following links: [Link1], [Link2], [Link3].