CVE-2020-24972
published 2020-08-29CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.72%
90.8th percentile
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kleopatra | < kleopatra 4:20.08.2-2 (bookworm) | kleopatra 4:20.08.2-2 (bookworm) |
| fedoraproject | fedora | — | — |
| kleopatra_project | kleopatra | < 20.07.80 | 20.07.80 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for Kleopatra process launches that include '-platformpluginpath' on the command line, which can be used to side-load an arbitrary DLL via a crafted openpgp4fpr: URL. ↗
- →Inspect URL handler registrations and browser/mail-client activity for openpgp4fpr: scheme invocations, as these can pass unsanitized command-line options to Kleopatra. ↗
- ·Vulnerability is fixed in Kleopatra 3.1.12 (and 20.07.80 or later); Debian packages resolved at version 4:20.08.2-2 across bookworm, bullseye, trixie, forky, and sid. ↗
- ·Despite being classified as remotely triggerable (via a crafted URL), Debian's tracker scopes the issue as 'local', meaning user interaction (clicking a malicious openpgp4fpr: link) is required. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p3w5-fpg6-wrh9: The Kleopatra component before 3
ghsa_unreviewed·2022-05-24
CVE-2020-24972 [MEDIUM] CWE-116 GHSA-p3w5-fpg6-wrh9: The Kleopatra component before 3
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
OSV
CVE-2020-24972: The Kleopatra component before 3
osv·2020-08-29·CVSS 8.8
CVE-2020-24972 [HIGH] CVE-2020-24972: The Kleopatra component before 3
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Debian
CVE-2020-24972: kleopatra - The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows rem...
vendor_debian·2020·CVSS 8.8
CVE-2020-24972 [HIGH] CVE-2020-24972: kleopatra - The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows rem...
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Scope: local
bookworm: resolved (fixed in 4:20.08.2-2)
bullseye: resolved (fixed in 4:20.08.2-2)
forky: resolved (fixed in 4:20.08.2-2)
sid: resolved (fixed in 4:20.08.2-2)
trixie: resolved (fixed in 4:20.08.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-24972 kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options [fedora-all]
bugzilla·2020-10-12·CVSS 8.8
CVE-2020-24972 [HIGH] CVE-2020-24972 kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options [fedora-all]
CVE-2020-24972 kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the R
Bugzilla
CVE-2020-24972 Kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options
bugzilla·2020-10-12·CVSS 8.8
CVE-2020-24972 [HIGH] CVE-2020-24972 Kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options
CVE-2020-24972 Kleopatra: allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
References:
https://dev.gnupg.org/rKLEOPATRAb4bd63c1739900d94c04da03045e9445a5a5f54b
https://dev.gnupg.org/source/kleo/browse/master/CMakeLists.txt
Discussion:
Created kleopatra tracking bugs for this issue:
Affects: fedora-all [bug 1887364]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not af
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00064.htmlhttps://dev.gnupg.org/rKLEOPATRAb4bd63c1739900d94c04da03045e9445a5a5f54bhttps://dev.gnupg.org/source/kleo/browse/master/CMakeLists.txthttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRIPL72WMXTVWS2M7WYV5SNPETYJ2YI7/https://security.gentoo.org/glsa/202008-21http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00064.htmlhttps://dev.gnupg.org/rKLEOPATRAb4bd63c1739900d94c04da03045e9445a5a5f54bhttps://dev.gnupg.org/source/kleo/browse/master/CMakeLists.txthttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRIPL72WMXTVWS2M7WYV5SNPETYJ2YI7/https://security.gentoo.org/glsa/202008-21
2020-08-29
Published