Logo
vulnerabilityCVE-2018-12020
Name
CVE-2018-12020
Source
NVD ( link)Debian ( link)
Description
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Published Date
Updated Date
Workaround
-
Advisories
https://usn.ubuntu.com/3675-1/Third Party Advisory
https://usn.ubuntu.com/3675-2/Third Party Advisory
https://usn.ubuntu.com/3675-3/Third Party Advisory
https://usn.ubuntu.com/3964-1/Third Party Advisory
https://usn.ubuntu.com/3675-1/Third Party Advisory
https://usn.ubuntu.com/3675-2/Third Party Advisory
https://usn.ubuntu.com/3675-3/Third Party Advisory
https://usn.ubuntu.com/3964-1/Third Party Advisory

Analysis#


Affected Component
Analysis
gnupg
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.4.23
Exploitable
buildroot
master
2.5.20
Not Affected
openwrt
master
1.4.23-r5
Exploitable
openwrt
master
2.5.20-r1
Not Affected
openwrt
openwrt-25.12
1.4.23-r5
Exploitable
openwrt
openwrt-25.12
2.4.8-r1
Not Affected
yocto
kirkstone
2.3.7
Not Affected
yocto
master
2.5.17
Not Affected
yocto
scarthgap
2.4.9
Not Affected