Download
| Alert*
[3.6] gnupg: filename sanitization problem (CVE-2018-12020)
GnuPG before version 2.2.8 does not properly sanitize original filenames of signed or encrypted messages allowing for the insertion of line feeds and other control characters. An attacker could exploit this by injecting such characters to craft status messages and fake the validity of signatures.
|