<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:13:33 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4490 — Moderate: gnupg2 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4490</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gnupg2, AlmaLinux:8: gnupg2-smime&lt;/p&gt;
&lt;p&gt;The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: gnupg2 (2.2.20). (BZ#1663944)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* GnuPG: interaction between the sks-keyserver code and GnuPG allows for a Certificate Spamming Attack which leads to persistent DoS (CVE-2019-13050)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gnupg2, AlmaLinux:8: gnupg2-smime&lt;/p&gt;
&lt;p&gt;The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: gnupg2 (2.2.20). (BZ#1663944)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* GnuPG: interaction between the sks-keyserver code and GnuPG allows for a Certificate Spamming Attack which leads to persistent DoS (CVE-2019-13050)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4490</guid>
    </item>
    <item>
      <title>bdu:2019-02942</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02942</link>
      <description>bdu:2019-02942</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02942</guid>
    </item>
    <item>
      <title>EUVD-2026-55393</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-55393</link>
      <description>EUVD-2026-55393</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-55393</guid>
    </item>
    <item>
      <title>fkie_cve-2019-13050</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-13050</link>
      <description>&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-13050</guid>
    </item>
    <item>
      <title>GHSA-ch5h-mpfr-fhxh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ch5h-mpfr-fhxh</link>
      <description>&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ch5h-mpfr-fhxh</guid>
    </item>
    <item>
      <title>gsd-2019-13050</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-13050</link>
      <description>gsd-2019-13050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-13050</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1917-1 — Security update for gpg2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1917-1</link>
      <description>&lt;p&gt;Security update for gpg2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gpg2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1917-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:2006-1 — Security update for gpg2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:2006-1</link>
      <description>&lt;p&gt;Security update for gpg2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gpg2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:2006-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-13050</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13050</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg2, Ubuntu:16.04:LTS: sks, Ubuntu:18.04:LTS: gnupg2, Ubuntu:18.04:LTS: sks, Ubuntu:20.04:LTS: sks&lt;/p&gt;
&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg2, Ubuntu:16.04:LTS: sks, Ubuntu:18.04:LTS: gnupg2, Ubuntu:18.04:LTS: sks, Ubuntu:20.04:LTS: sks&lt;/p&gt;
&lt;p&gt;Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-13050</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
