Mark CVE -2018-19205 as ignored for stretch
The respective feature would rely on a properly working php-crypt-gpg installation. Those might be custom on the system (as php-crypt-gpg is not in stretch). But plugins/enigma/lib/enigma_driver_gnupg.php from 1.2.x has bigger issues anyway, since it's decrypt() function doesn't verify signatures on encrypted message.
Loading
Please register or sign in to comment