CVE-2020-24972Improper Encoding or Escaping of Output in Project Kleopatra

Severity
8.8HIGHNVD
EPSS
21.3%
top 4.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 24

Description

The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Also affects: Fedora 32

Patches

🔴Vulnerability Details

3
GHSA
GHSA-p3w5-fpg6-wrh9: The Kleopatra component before 32022-05-24
CVEList
CVE-2020-24972: The Kleopatra component before 32020-08-29
OSV
CVE-2020-24972: The Kleopatra component before 32020-08-29

📋Vendor Advisories

1
Debian
CVE-2020-24972: kleopatra - The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows rem...2020

💬Community

2
Bugzilla
CVE-2020-24972 kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options [fedora-all]2020-10-12
Bugzilla
CVE-2020-24972 Kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options2020-10-12
CVE-2020-24972 — Project Kleopatra vulnerability | cvebase