CNNVD-202511-2032 Information

CNNVD ID

CNNVD-202511-2032

CVE-2025-34324

  • CNNVD Published: 2025-11-18

Description (Chinese)

GoSign Desktop是立陶宛GoSign公司的一个电子文件签署软件。 GoSign Desktop 2.4.0及之前版本存在安全漏洞,该漏洞源于更新清单未签名且TLS证书验证可被禁用,可能导致任意代码执行。

Description (English)

GoSign Desktop is an electronic document signing software for GoSign, Lithuania. There is a security loophole in GoSign Desktop 2.4.0 and earlier versions, which stems from the fact that the updated list is not signed and TLS certificate certification can be disabled, which may lead to any code execution.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

GoSign

Published

2025-11-18

Last Modified

2026-02-24

References

https://www.ush.it/2025/11/14/vulnerabilita-multiple-gosign-desktop-esecuzione-remota-codice-arbitrario/ https://www.ush.it/2025/11/14/multiple-vulnerabilities-gosign-desktop-remote-code-execution/ https://www.vulncheck.com/advisories/gosign-desktop-insecure-update-mechanism-rce https://infocert.digital/consumer/gosign-suite/ https://access.redhat.com/security/cve/cve-2025-34324

Share on: