CVE-2013-4351
published 2013-10-10CVE-2013-4351: GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which…
PriorityP429medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.52%
83.1th percentile
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnupg2 | < gnupg2 2.0.22-1 (bookworm) | gnupg2 2.0.22-1 (bookworm) |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2013-10-09·CVSS 5.8
CVE-2013-4351 [MEDIUM] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Daniel Kahn Gillmor discovered that GnuPG treated keys with empty usage
flags as being valid for all usages. (CVE-2013-4351)
Taylor R Campbell discovered that GnuPG incorrectly handled certain OpenPGP
messages. If a user or automated system were tricked into processing a
specially-crafted message, GnuPG could consume resources, resulting in a
denial of service. (CVE-2013-4402)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnupg: treats no-usage-permitted keys as all-usages-permitted
vendor_redhat·2013-03-12·CVSS 5.8
CVE-2013-4351 [MEDIUM] gnupg: treats no-usage-permitted keys as all-usages-permitted
gnupg: treats no-usage-permitted keys as all-usages-permitted
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
Package: gnupg2 (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4351: gnupg2 - GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared...
vendor_debian·2013·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351: gnupg2 - GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared...
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
Scope: local
bookworm: resolved (fixed in 2.0.22-1)
bullseye: resolved (fixed in 2.0.22-1)
forky: resolved (fixed in 2.0.22-1)
sid: resolved (fixed in 2.0.22-1)
trixie: resolved (fixed in 2.0.22-1)
GHSA
GHSA-c6gv-ggmm-8j39: GnuPG 1
ghsa_unreviewed·2022-05-17
CVE-2013-4351 [MEDIUM] GHSA-c6gv-ggmm-8j39: GnuPG 1
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
OSV
CVE-2013-4351: GnuPG 1
osv·2013-10-10·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351: GnuPG 1
GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4351 gnupg: treats no-usage-permitted keys as all-usages-permitted
bugzilla·2013-09-20·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351 gnupg: treats no-usage-permitted keys as all-usages-permitted
CVE-2013-4351 gnupg: treats no-usage-permitted keys as all-usages-permitted
GnuPG and GnuPG2 are found to have a flaw, where the key flags are misinterpreted, which could possibly lead to a breach of confidentiality or a mistaken identity verification. Key flags are the packets, that indicated the capabilities of the key, represented as binary flags. The issue is that if a key or subkey has this "key flags" subpacket attached with all bits cleared (off), GnuPG currently treats the key as having all bits set (on), though the thing to note is that the keys with this sort of marker are very rare in the wild.
The risks are unlikely today, and they are not particularly dangerous, but the keyholder's stated intent of separating out keys by context of use is being ignored, so there is a window o
Bugzilla
CVE-2013-4351 GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
bugzilla·2013-09-20·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351 GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
CVE-2013-4351 GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [epel-5]
bugzilla·2013-09-20·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [epel-5]
CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5
Bugzilla
CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
bugzilla·2013-09-20·CVSS 5.8
CVE-2013-4351 [MEDIUM] CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
CVE-2013-4351 gnupg2: GnuPG: treats no-usage-permitted keys as all-usages-permitted [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
http://lists.opensuse.org/opensuse-updates/2013-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1459.htmlhttp://thread.gmane.org/gmane.comp.encryption.gpg.devel/17712/focus=18138http://ubuntu.com/usn/usn-1987-1http://www.debian.org/security/2013/dsa-2773http://www.debian.org/security/2013/dsa-2774http://www.openwall.com/lists/oss-security/2013/09/13/4https://bugzilla.redhat.com/show_bug.cgi?id=1010137http://lists.opensuse.org/opensuse-updates/2013-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1459.htmlhttp://thread.gmane.org/gmane.comp.encryption.gpg.devel/17712/focus=18138http://ubuntu.com/usn/usn-1987-1http://www.debian.org/security/2013/dsa-2773http://www.debian.org/security/2013/dsa-2774http://www.openwall.com/lists/oss-security/2013/09/13/4https://bugzilla.redhat.com/show_bug.cgi?id=1010137
2013-10-10
Published