USN-4839-1
Dashboard / Vulnerabilities / USN-4839-1
USN-4839-1
Summary: python-gnupg vulnerabilities
Details: Marcus Brinkmann discovered that python-gnupg improperly handled certain command line parameters. A remote attacker could use this to spoof the output of python-gnupg and cause unsigned e-mail to appear signed. (CVE-2018-12020) It was discovered that python-gnupg incorrectly handled the GPG passphrase. A remote attacker could send a specially crafted passphrase that would allow them to control the output of encryption and decryption operations. (CVE-2019-6690)
References: https://ubuntu.com/security/notices/USN-4839-1, https://ubuntu.com/security/CVE-2018-12020, https://ubuntu.com/security/CVE-2019-6690
Affected packages
Package
Name: python-gnupg
Purl: pkg:deb/ubuntu/python-gnupg?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
