CVE-2019-14855: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
Affected products
- Canonical Ubuntu Linux: version 18.04 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Gnupg Gnupg: before 2.2.18 (fixed in 2.2.18)
Published 2020-03-20. Last modified 2026-06-17.