gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
{ "ubuntu_priority": "medium" }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.10-2", "binary_name": "signing-party" }, { "binary_version": "2.10-2", "binary_name": "signing-party-dbgsym" } ] }