GHSA-qh62-ch95-63wh
Dashboard / Vulnerabilities / GHSA-qh62-ch95-63wh
GHSA-qh62-ch95-63wh
Summary: Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended
Details: **Withdrawn:** Duplicate of GHSA-2fch-jvg5-crf6
References: https://nvd.nist.gov/vuln/detail/CVE-2019-6690, https://bitbucket.org/vinay.sajip/python-gnupg/commits/1a5196800604c05f9e347110b4ecca538ba68cdc, https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability, https://github.com/advisories/GHSA-2fch-jvg5-crf6, https://github.com/advisories/GHSA-qh62-ch95-63wh, https://github.com/pypa/advisory-database/tree/main/vulns/python-gnupg/PYSEC-2019-115.yaml, https://lists.debian.org/debian-lts-announce/2019/02/msg00021.html, https://lists.fedoraproject.org/archives/list/[email protected]/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47, https://lists.fedoraproject.org/archives/list/[email protected]/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7II, https://lists.fedoraproject.org/archives/list/[email protected]/message/X4VFRUG56542LTYK4444TPJBGR57MT25, https://pypi.org/project/python-gnupg/#history, https://seclists.org/bugtraq/2019/Jan/41, https://usn.ubuntu.com/3964-1, http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00008.html, http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00058.html, http://packetstormsecurity.com/files/151341/Python-GnuPG-0.4.3-Improper-Input-Validation.html, http://www.securityfocus.com/bid/106756
Affected packages
Package
Name: python-gnupg
Purl: pkg:pypi/python-gnupg
Affected ranges
Type: ECOSYSTEM
Events:
