CVE-2018-9234
published 2018-04-04CVE-2018-9234: GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.08%
79.4th percentile
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | gnupg2 | < gnupg2 2.2.7-1 (bookworm) | gnupg2 2.2.7-1 (bookworm) |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | >= 0 < 1.4.16-1ubuntu2.5 | 1.4.16-1ubuntu2.5 |
| gnupg | gnupg | >= 0 < 1.4.20-1ubuntu3.2 | 1.4.20-1ubuntu3.2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GnuPG vulnerabilities
vendor_ubuntu·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] GnuPG vulnerabilities
Title: GnuPG vulnerabilities
Summary: Several security issues were fixed in GnuPG.
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)
Lance Vick discovered that GnuPG did not enforce configurations where
key certification required an offline primary Certify key. An attacker
with access to a signing subkey could generate certifications that
appeared to be valid. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-9234)
Instructions: In general, a standard system update will
Red Hat
GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
vendor_redhat·2018-03-19·CVSS 7.5
CVE-2018-9234 [HIGH] CWE-325 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
Package: gnupg (Red Hat Enterprise Linux 5) - Will not fix
Package: gnupg2 (Red Hat Enterprise Linux 5) - Will not fix
Package: gnupg2 (Red Hat Enterprise Linux 6) - Fix deferred
Package: gnupg2 (Red Hat Enterprise Linux 7) - Fix deferred
Package: gnupg (Red Hat Enterprise Linux 8) - Not affected
Package: gnupg2 (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-9234: gnupg2 - GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certificatio...
vendor_debian·2018·CVSS 7.5
CVE-2018-9234 [HIGH] CVE-2018-9234: gnupg2 - GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certificatio...
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
Scope: local
bookworm: resolved (fixed in 2.2.7-1)
bullseye: resolved (fixed in 2.2.7-1)
forky: resolved (fixed in 2.2.7-1)
sid: resolved (fixed in 2.2.7-1)
trixie: resolved (fixed in 2.2.7-1)
GHSA
GHSA-mq99-p8pq-jp4q: GnuPG 2
ghsa_unreviewed·2022-05-14
CVE-2018-9234 [HIGH] GHSA-mq99-p8pq-jp4q: GnuPG 2
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
OSV
gnupg, gnupg2 vulnerabilities
osv·2018-06-11·CVSS 7.5
CVE-2018-12020 [HIGH] gnupg, gnupg2 vulnerabilities
gnupg, gnupg2 vulnerabilities
Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)
Lance Vick discovered that GnuPG did not enforce configurations where
key certification required an offline primary Certify key. An attacker
with access to a signing subkey could generate certifications that
appeared to be valid. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-9234)
OSV
CVE-2018-9234: GnuPG 2
osv·2018-04-04·CVSS 7.5
CVE-2018-9234 [HIGH] CVE-2018-9234: GnuPG 2
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
bugzilla·2018-04-05·CVSS 7.5
CVE-2018-9234 [HIGH] CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
Bugzilla
CVE-2018-9234 gnupg2: GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
bugzilla·2018-04-05·CVSS 7.5
CVE-2018-9234 [HIGH] CVE-2018-9234 gnupg2: GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
CVE-2018-9234 gnupg2: GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
bugzilla·2018-04-05·CVSS 7.5
CVE-2018-9234 [HIGH] CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
CVE-2018-9234 GnuPG: Unenforced configuration allows for apparently valid certifications actually signed by signing subkeys
GnuPG through version 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
Upstream Issue:
https://dev.gnupg.org/T3844
Upstream Patch:
https://dev.gnupg.org/rGa17d2d1f690ebe5d005b4589a5fe378b6487c657
Discussion:
Created gnupg2 tracking bugs for this issue:
Affects: fedora-all [bug 1563931]
Created gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1563932]
---
Analysis:
Normally master keys are more protected than signing or encryption subkeys. Since master key can actually be used to prove
2018-04-04
Published