CVE Feed

    Dashboard / CVE / CVE-2020-24972

    CVE-2020-24972

    The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

    Published:Aug 29, 2020
    Last Modified:Nov 21, 2024
    EPS:Aug 29, 2020
    EPSS Score:0.20708
    CVSS Score:8.8

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Kleopatra Project
    Product
    Kleopatra
    Vendor
    Opensuse
    Product
    Backports Sle
    Vendor
    Opensuse
    Product
    Leap

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High