CVE-2018-12020
published 2018-06-08CVE-2018-12020: mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
8.65%
94.5th percentile
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | enigmail | < enigmail 2:2.0.7-1 (bullseye) | enigmail 2:2.0.7-1 (bullseye) |
| debian | gnupg1 | < enigmail 2:2.0.7-1 (bullseye) | enigmail 2:2.0.7-1 (bullseye) |
| debian | gnupg2 | < enigmail 2:2.0.7-1 (bullseye) | enigmail 2:2.0.7-1 (bullseye) |
| enigmail | enigmail | >= 0 < 2:2.0.7-1 | 2:2.0.7-1 |
| gnupg | gnupg | < 2.2.8 | 2.2.8 |
| gnupg | gnupg | >= 0 < 1.4.16-1ubuntu2.5 | 1.4.16-1ubuntu2.5 |
| gnupg | gnupg | >= 0 < 1.4.20-1ubuntu3.2 | 1.4.20-1ubuntu3.2 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.1-1ubuntu1.18.04.1 | 0.4.1-1ubuntu1.18.04.1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1ubuntu0.1~esm1 | 0.3.6-1ubuntu0.1~esm1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.8-2ubuntu0.1~esm1 | 0.3.8-2ubuntu0.1~esm1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-678p-6r6j-65f9: mainproc
ghsa_unreviewed·2022-05-13
CVE-2018-12020 [HIGH] CWE-706 GHSA-678p-6r6j-65f9: mainproc
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
OSV
python-gnupg vulnerabilities
osv·2021-03-15·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
python-gnupg vulnerabilities
Marcus Brinkmann discovered that python-gnupg improperly handled certain
command line parameters. A remote attacker could use this to spoof the
output of python-gnupg and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase.
A remote attacker could send a specially crafted passphrase that would
allow them to control the output of encryption and decryption operations.
(CVE-2019-6690)
OSV
python-gnupg vulnerabilities
osv·2019-05-02·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
python-gnupg vulnerabilities
Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain
command line parameters. A remote attacker could use this to spoof the output of
GnuPG and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase. A
remote attacker could send a specially crafted passphrase that would allow them
to control the output of encryption and decryption operations.
(CVE-2019-6690)
OSV
gnupg, gnupg2 vulnerabilities
osv·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] gnupg, gnupg2 vulnerabilities
gnupg, gnupg2 vulnerabilities
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)
Lance Vick discovered that GnuPG did not enforce configurations where
key certification required an offline primary Certify key. An attacker
with access to a signing subkey could generate certifications that
appeared to be valid. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-9234)
OSV
CVE-2018-12020: mainproc
osv·2018-06-08·CVSS 7.5
CVE-2018-12020 [HIGH] CVE-2018-12020: mainproc
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Ubuntu
python-gnupg vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 7.5
CVE-2019-6690 [HIGH] python-gnupg vulnerabilities
Title: python-gnupg vulnerabilities
Summary: Several security issues were fixed in python-gnupg.
Marcus Brinkmann discovered that python-gnupg improperly handled certain
command line parameters. A remote attacker could use this to spoof the
output of python-gnupg and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase.
A remote attacker could send a specially crafted passphrase that would
allow them to control the output of encryption and decryption operations.
(CVE-2019-6690)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
python-gnupg vulnerabilities
vendor_ubuntu·2019-05-02·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
Title: python-gnupg vulnerabilities
Summary: Several security issues were fixed in python-gnupg
Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain
command line parameters. A remote attacker could use this to spoof the output of
GnuPG and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase. A
remote attacker could send a specially crafted passphrase that would allow them
to control the output of encryption and decryption operations.
(CVE-2019-6690)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2018-06-18·CVSS 7.5
CVE-2018-12020 [HIGH] GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to incorrectly interpret the status of the cryptographic operation
if it received specially crafted file.
USN-3675-1 fixed a vulnerability in GnuPG. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG 2 vulnerability
vendor_ubuntu·2018-06-15
CVE-2018-12020 GnuPG 2 vulnerability
Title: GnuPG 2 vulnerability
Summary: GnuPG 2 could be made to present validity information incorrectly.
USN-3675-1 fixed a vulnerability in GnuPG 2 for Ubuntu 18.04 LTS and
Ubuntu 17.10. This update provides the corresponding update for GnuPG 2
in Ubuntu 16.04 LTS and Ubuntu 14.04 LTS.
Original advisory details:
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)
Lance Vick discovered that GnuPG did not enforce configurations where
key certification required an offline primary Certify key. An attacker
with access to a signing subkey could generate certifications that
appeared to be valid. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-9234)
Instructions: In general, a standard system update will
Red Hat
gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
vendor_redhat·2018-06-08·CVSS 7.5
CVE-2018-12020 [HIGH] CWE-20 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
A data validation flaw was found in the way gnupg processes file names during decryption and signature validation. An attacker may be able to inject messages into gnupg verbose message logging which may have the potential to bypass the integrity of signature
Debian
CVE-2018-12020: enigmail - mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decrypt...
vendor_debian·2018·CVSS 7.5
CVE-2018-12020 [HIGH] CVE-2018-12020: enigmail - mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decrypt...
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Scope: local
bullseye: resolved (fixed in 2:2.0.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12020 gnupg: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
bugzilla·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] CVE-2018-12020 gnupg: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
CVE-2018-12020 gnupg: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM change
Bugzilla
CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
bugzilla·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
GnuPG before version 2.2.8 does not properly sanitize original filenames of signed or encrypted messages allowing for the insertion of line feeds and other control characters. An attacker could exploit this by injecting such characters to craft status messages and fake the validity of signatures.
External Reference:
https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html
Upstream Issue:
https://dev.gnupg.org/T4012
Upstream Patches:
https://dev.gnupg.org/rG2326851c60793653069494379b16d84e4c10a0ac
https://dev.gnupg.org/rG210e402acd3e284b32db1901e43bf1470e659e49
https://dev.gnupg.org/rG13f135c7a252cc46cff96e75968d92b6dc8dce1b
Bugzilla
CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
bugzilla·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
CVE-2018-12020 gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
http://openwall.com/lists/oss-security/2018/06/08/2http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlhttp://seclists.org/fulldisclosure/2019/Apr/38http://www.openwall.com/lists/oss-security/2019/04/30/4http://www.securityfocus.com/bid/104450http://www.securitytracker.com/id/1041051https://access.redhat.com/errata/RHSA-2018:2180https://access.redhat.com/errata/RHSA-2018:2181https://dev.gnupg.org/T4012https://github.com/RUB-NDS/Johnny-You-Are-Firedhttps://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdfhttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.htmlhttps://usn.ubuntu.com/3675-1/https://usn.ubuntu.com/3675-2/https://usn.ubuntu.com/3675-3/https://usn.ubuntu.com/3964-1/https://www.debian.org/security/2018/dsa-4222https://www.debian.org/security/2018/dsa-4223https://www.debian.org/security/2018/dsa-4224http://openwall.com/lists/oss-security/2018/06/08/2http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlhttp://seclists.org/fulldisclosure/2019/Apr/38http://www.openwall.com/lists/oss-security/2019/04/30/4http://www.securityfocus.com/bid/104450http://www.securitytracker.com/id/1041051https://access.redhat.com/errata/RHSA-2018:2180https://access.redhat.com/errata/RHSA-2018:2181https://dev.gnupg.org/T4012https://github.com/RUB-NDS/Johnny-You-Are-Firedhttps://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdfhttps://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.htmlhttps://usn.ubuntu.com/3675-1/https://usn.ubuntu.com/3675-2/https://usn.ubuntu.com/3675-3/https://usn.ubuntu.com/3964-1/https://www.debian.org/security/2018/dsa-4222https://www.debian.org/security/2018/dsa-4223https://www.debian.org/security/2018/dsa-4224
2018-06-08
Published