CVE-2019-6690
published 2019-03-21CVE-2019-6690: python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
8.55%
94.5th percentile
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-gnupg | < python-gnupg 0.4.4-1 (bookworm) | python-gnupg 0.4.4-1 (bookworm) |
| opensuse | leap | — | — |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.4-1 | 0.4.4-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.4-1 | 0.4.4-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.4-1 | 0.4.4-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.4-1 | 0.4.4-1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.4 | 0.4.4 |
| python-gnupg_project | python-gnupg | >= 0 < 0.4.1-1ubuntu1.18.04.1 | 0.4.1-1ubuntu1.18.04.1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.6-1ubuntu0.1~esm1 | 0.3.6-1ubuntu0.1~esm1 |
| python-gnupg_project | python-gnupg | >= 0 < 0.3.8-2ubuntu0.1~esm1 | 0.3.8-2ubuntu0.1~esm1 |
| python | python-gnupg | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-gnupg vulnerabilities
osv·2021-03-15·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
python-gnupg vulnerabilities
Marcus Brinkmann discovered that python-gnupg improperly handled certain
command line parameters. A remote attacker could use this to spoof the
output of python-gnupg and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase.
A remote attacker could send a specially crafted passphrase that would
allow them to control the output of encryption and decryption operations.
(CVE-2019-6690)
OSV
Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended
osv·2020-03-13
CVE-2019-6690 [MEDIUM] Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended
Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended
**Withdrawn:** Duplicate of GHSA-2fch-jvg5-crf6
OSV
python-gnupg vulnerabilities
osv·2019-05-02·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
python-gnupg vulnerabilities
Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain
command line parameters. A remote attacker could use this to spoof the output of
GnuPG and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase. A
remote attacker could send a specially crafted passphrase that would allow them
to control the output of encryption and decryption operations.
(CVE-2019-6690)
GHSA
Improper Input Validation python-gnupg
ghsa·2019-03-25
CVE-2019-6690 [HIGH] CWE-20 Improper Input Validation python-gnupg
Improper Input Validation python-gnupg
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
OSV
Improper Input Validation python-gnupg
osv·2019-03-25
CVE-2019-6690 [HIGH] Improper Input Validation python-gnupg
Improper Input Validation python-gnupg
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
OSV
CVE-2019-6690: python-gnupg 0
osv·2019-03-21·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690: python-gnupg 0
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
Ubuntu
python-gnupg vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 7.5
CVE-2019-6690 [HIGH] python-gnupg vulnerabilities
Title: python-gnupg vulnerabilities
Summary: Several security issues were fixed in python-gnupg.
Marcus Brinkmann discovered that python-gnupg improperly handled certain
command line parameters. A remote attacker could use this to spoof the
output of python-gnupg and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase.
A remote attacker could send a specially crafted passphrase that would
allow them to control the output of encryption and decryption operations.
(CVE-2019-6690)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
python-gnupg vulnerabilities
vendor_ubuntu·2019-05-02·CVSS 7.5
CVE-2018-12020 [HIGH] python-gnupg vulnerabilities
Title: python-gnupg vulnerabilities
Summary: Several security issues were fixed in python-gnupg
Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain
command line parameters. A remote attacker could use this to spoof the output of
GnuPG and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase. A
remote attacker could send a specially crafted passphrase that would allow them
to control the output of encryption and decryption operations.
(CVE-2019-6690)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
vendor_redhat·2019-01-23·CVSS 7.5
CVE-2019-6690 [HIGH] CWE-20 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
Statement: The issue affects the versions of python-gnupg shipped with Red Hat Update Infrastructure 3, however the vulnerable functions are never used by the product.
The issue affects the versions of python-gnupg shipped with Red Hat Satellite 6, however the vulnerable functions are never used by the product.
Mitigation: Filter out newlines from passphrases before passing
Debian
CVE-2019-6690: python-gnupg - python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt ...
vendor_debian·2019·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690: python-gnupg - python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt ...
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
Scope: local
bookworm: resolved (fixed in 0.4.4-1)
bullseye: resolved (fixed in 0.4.4-1)
forky: resolved (fixed in 0.4.4-1)
sid: resolved (fixed in 0.4.4-1)
trixie: resolved (fixed in 0.4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-7]
bugzilla·2019-01-29·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-7]
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the fol
Bugzilla
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [fedora-all]
bugzilla·2019-01-29·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [fedora-all]
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-6]
bugzilla·2019-01-29·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-6]
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt() [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the fol
Bugzilla
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
bugzilla·2019-01-29·CVSS 7.5
CVE-2019-6690 [HIGH] CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
CVE-2019-6690 python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()
From the source :
We discovered a way to inject data through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods when symmetric encryption is used.
The supplied passphrase is not validated for newlines, and the library passes --passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted or plaintext to be encrypted on subsequent lines.
By supplying a passphrase containing a newline an attacker can control/modify the ciphertext/plaintext being decrypted/encrypted.
Vulnerable in: python-gnupg 0.4.3 and maybe earlier versions.
Mitigation : Users should upgrade to python-gnupg 0.4.4
Upstre
http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-02/msg00058.htmlhttp://packetstormsecurity.com/files/151341/Python-GnuPG-0.4.3-Improper-Input-Validation.htmlhttp://www.securityfocus.com/bid/106756https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability/https://lists.debian.org/debian-lts-announce/2019/02/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7II/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4VFRUG56542LTYK4444TPJBGR57MT25/https://pypi.org/project/python-gnupg/#historyhttps://seclists.org/bugtraq/2019/Jan/41https://usn.ubuntu.com/3964-1/http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-02/msg00058.htmlhttp://packetstormsecurity.com/files/151341/Python-GnuPG-0.4.3-Improper-Input-Validation.htmlhttp://www.securityfocus.com/bid/106756https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability/https://lists.debian.org/debian-lts-announce/2019/02/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7II/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4VFRUG56542LTYK4444TPJBGR57MT25/https://pypi.org/project/python-gnupg/#historyhttps://seclists.org/bugtraq/2019/Jan/41https://usn.ubuntu.com/3964-1/
2019-03-21
Published