[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.7] gnupg: filename sanitization problem (CVE-2018-12020)

ID: oval:org.secpod.oval:def:1801009Date: (C)2018-06-18   (M)2022-08-29
Class: PATCHFamily: unix




GnuPG before version 2.2.8 does not properly sanitize original filenames of signed or encrypted messages allowing for the insertion of line feeds and other control characters. An attacker could exploit this by injecting such characters to craft status messages and fake the validity of signatures.

Platform:
Alpine Linux 3.7
Product:
gnupg
Reference:
8994
CVE-2018-12020
CVE    1
CVE-2018-12020
CPE    2
cpe:/o:alpinelinux:alpine_linux:3.7
cpe:/a:gnupg:gnupg

© SecPod Technologies