cbcvebase.
CVE-2020-24972
published 2020-08-29

CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiankleopatra< kleopatra 4:20.08.2-2 (bookworm)kleopatra 4:20.08.2-2 (bookworm)
fedoraprojectfedora
kleopatra_projectkleopatra< 20.07.8020.07.80
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
opensusebackports_sle
opensuseleap

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH