GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array...
Vulnerability Description
GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-25125
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.opensuse.org/show_bug.cgi?id=1176034
- https://dev.gnupg.org/rG8ec9573e57866dda5efb4677d4454161517484bc
- https://lists.gnupg.org/pipermail/gnupg-announce/2020q3/000448.html
- https://dev.gnupg.org/T5050
- http://www.openwall.com/lists/oss-security/2020/09/03/4
- http://www.openwall.com/lists/oss-security/2020/09/03/5
More from gnupg
View All →Affected Vendor
gnupg
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.