CVE-2020-24972 — Improper Encoding or Escaping of Output in Project Kleopatra
Severity
8.8HIGHNVD
EPSS
21.3%
top 4.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 24
Description
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
Also affects: Fedora 32
Patches
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2020-24972: kleopatra - The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows rem...↗2020
💬Community
2Bugzilla▶
CVE-2020-24972 kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options [fedora-all]↗2020-10-12
Bugzilla▶
CVE-2020-24972 Kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options↗2020-10-12