{"id":"ECHO-7da4-e7c5-9582","summary":"Disputed by GnuPG maintainer Werner Koch. The vulnerability involves form feed\ncharacter handling in cleartext signatures. The maintainer states this is \"wrong\nusage of a tool or social engineering\" and not a real vulnerability.\nSee: https://gnupg.org/blog/20251226-cleartext-signatures.html\nDebian classifies this as \"Minor issue\" with no fix planned.\nNo fix exists in any Debian version (including sid).\n","modified":"2026-09-15T03:33:43.454022580Z","published":"2025-12-28T14:02:34.509885Z","withdrawn":"2026-02-19T10:00:04.917Z","upstream":["CVE-2025-68972"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-68972"}],"affected":[{"package":{"name":"gnupg2","ecosystem":"Echo","purl":"pkg:deb/echo/gnupg2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.8-5+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-7da4-e7c5-9582.json"}}],"schema_version":"1.9.0"}