{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3atlsfuzzerecdsapython/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tlsfuzzer:ecdsa:*:*:*:*:*:python:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2024-23342"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GnuPG"],"_cs_severities":["low"],"_cs_tags":["informational","vulnerability"],"_cs_type":"advisory","_cs_vendors":["GnuPG"],"content_html":"\u003cp\u003eThe German Federal Office for Information Security (BSI) has reported a vulnerability in GnuPG that allows a remote, anonymous attacker to perform unauthorized file manipulation. The flaw, tracked as CVE-2024-23342, potentially impacts the integrity of processed files. GnuPG is a widely used tool for data encryption and digital signatures. Because the vulnerability allows for external influence over file content, it represents a significant risk for systems that rely on GnuPG to verify the authenticity or maintain the integrity of data. Defenders should track updates from the GnuPG project to ensure the latest patches are applied, as no specific exploitation vector is currently detailed in the advisory.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability enables file manipulation, which could lead to unauthorized modification of sensitive data, bypassing of integrity checks, or the corruption of critical system files relying on GnuPG signatures. The scale of potential victims includes any infrastructure or application utilizing affected versions of GnuPG for file handling or signature verification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for official patch releases from the GnuPG project for CVE-2024-23342. Since no specific exploitation indicators are currently available, implement integrity monitoring on critical files processed by GnuPG to detect unauthorized changes.\u003c/p\u003e\n","date_modified":"2026-10-06T12:44:04Z","date_published":"2026-10-06T12:44:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gnupg-file-manipulation/","summary":"A vulnerability in GnuPG identified as CVE-2024-23342 allows a remote, anonymous attacker to manipulate files, posing a risk to data integrity.","title":"GnuPG File Manipulation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-gnupg-file-manipulation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:tlsfuzzer:ecdsa:*:*:*:*:*:python:*:*","version":"https://jsonfeed.org/version/1.1"}