CVE-2019-13050 describes a denial-of-service vulnerability affecting GnuPG versions through 2.2.16 and the SKS keyserver network through 1.2.0. This flaw allows attackers to cause a persistent denial of service through a Certificate Spamming Attack when GnuPG is configured to retrieve data from the SKS keyserver network. Rated with a CVSS score of 7.5 (High), this vulnerability has a network attack vector, low attack complexity, and high availability impact, with no confidentiality or integrity impact. While there is no evidence of active exploitation, exploit code is not publicly available, and it is not listed on the KEV catalog, community discussion and media coverage indicate awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.16CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* | ||
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:sks_keyserver_project:sks_keyserver:*:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.