CVE-2019-13050

HIGH

GnuPG < 2.2.16 - Denial of Service via SKS Keyserver Certificate Spamming

Title source: llm
STIX 2.1

Description

Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.

References (11)

Core 11
Core References
Exploit, Issue Tracking, Mitigation, Third Party Advisory x_refsource_misc
https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f
Third Party Advisory x_refsource_misc
https://twitter.com/lambdafu/status/1147162583969009664
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00039.html
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K08654551

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-295
Status published
Products (7)
f5/traffix_signaling_delivery_controller 5.0.0 - 5.1.0
fedoraproject/fedora 29
fedoraproject/fedora 30
gnupg/gnupg < 2.2.16
opensuse/leap 15.0
opensuse/leap 15.1
sks_keyserver_project/sks_keyserver < 1.2.0
Published Jun 29, 2019
Tracked Since Feb 18, 2026