Skip to content
Threat Feed
low advisory

GnuPG File Manipulation Vulnerability

A vulnerability in GnuPG identified as CVE-2024-23342 allows a remote, anonymous attacker to manipulate files, posing a risk to data integrity.

CVE search metadata

CVE search record: CVE-2024-23342. Severity: high. CVSS: 7.4. EPSS: 0.98%. KEV: no. Product: GnuPG. Brief: GnuPG File Manipulation Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gnupg-file-manipulation/

The German Federal Office for Information Security (BSI) has reported a vulnerability in GnuPG that allows a remote, anonymous attacker to perform unauthorized file manipulation. The flaw, tracked as CVE-2024-23342, potentially impacts the integrity of processed files. GnuPG is a widely used tool for data encryption and digital signatures. Because the vulnerability allows for external influence over file content, it represents a significant risk for systems that rely on GnuPG to verify the authenticity or maintain the integrity of data. Defenders should track updates from the GnuPG project to ensure the latest patches are applied, as no specific exploitation vector is currently detailed in the advisory.

Impact

The successful exploitation of this vulnerability enables file manipulation, which could lead to unauthorized modification of sensitive data, bypassing of integrity checks, or the corruption of critical system files relying on GnuPG signatures. The scale of potential victims includes any infrastructure or application utilizing affected versions of GnuPG for file handling or signature verification.

Recommendation

Prioritize monitoring for official patch releases from the GnuPG project for CVE-2024-23342. Since no specific exploitation indicators are currently available, implement integrity monitoring on critical files processed by GnuPG to detect unauthorized changes.

Enrichment needed

  • CVE-2024-23342 (CTI) Monitor for detailed technical advisories or PoC releases to refine defense.

Mitigations

Monitor for the release of GnuPG security patches for CVE-2024-23342 and apply to all relevant infrastructure.

medium_term IT Operations

CVE-2024-23342