UBUNTU-CVE-2018-12020
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12020
UBUNTU-CVE-2018-12020
Summary:
Details: mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
References: https://ubuntu.com/security/CVE-2018-12020, https://dev.gnupg.org/T4012, https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html, https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=210e402acd3e284b32db1901e43bf1470e659e49, https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=2326851c60793653069494379b16d84e4c10a0ac, https://ubuntu.com/security/notices/USN-3675-1, https://sourceforge.net/p/enigmail/forum/announce/thread/b948279f/, https://neopg.io/blog/gpg-signature-spoof/, https://ubuntu.com/security/notices/USN-3675-2, https://ubuntu.com/security/notices/USN-3675-3, https://ubuntu.com/security/notices/USN-3964-1, https://ubuntu.com/security/notices/USN-4839-1, https://www.cve.org/CVERecord?id=CVE-2018-12020
Affected packages
Package
Name: gnupg
Purl: pkg:deb/ubuntu/gnupg?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
