ECHO-7da4-e7c5-9582

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-7da4-e7c5-9582.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-7da4-e7c5-9582
Upstream
Withdrawn
2026-02-19T10:00:04Z
Published
2025-12-28T14:02:34Z
Modified
2026-09-15T03:33:43Z
Summary
Disputed by GnuPG maintainer Werner Koch. The vulnerability involves form feed character handling in cleartext signatures. The maintainer states this is "wrong usage of a tool or social engineering" and not a real vulnerability. See: https://gnupg.org/blog/20251226-cleartext-signatures.html Debian classifies this as "Minor issue" with no fix planned. No fix exists in any Debian version (including sid).
Details
References

Affected packages

Echo / gnupg2

Package

Name
gnupg2
Purl
pkg:deb/echo/gnupg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.8-5+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-7da4-e7c5-9582.json"