USN-3964-1
Dashboard / Vulnerabilities / USN-3964-1
USN-3964-1
Summary: python-gnupg vulnerabilities
Details: Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain command line parameters. A remote attacker could use this to spoof the output of GnuPG and cause unsigned e-mail to appear signed. (CVE-2018-12020) It was discovered that python-gnupg incorrectly handled the GPG passphrase. A remote attacker could send a specially crafted passphrase that would allow them to control the output of encryption and decryption operations. (CVE-2019-6690)
References: https://ubuntu.com/security/notices/USN-3964-1, https://ubuntu.com/security/CVE-2018-12020, https://ubuntu.com/security/CVE-2019-6690
Affected packages
Package
Name: python-gnupg
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
