cbcvebase.
CVE-2020-24972
published 2020-08-29

CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported…

PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.72%
90.8th percentile
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiankleopatra< kleopatra 4:20.08.2-2 (bookworm)kleopatra 4:20.08.2-2 (bookworm)
fedoraprojectfedora
kleopatra_projectkleopatra< 20.07.8020.07.80
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
kleopatra_projectkleopatra>= 0 < 4:20.08.2-24:20.08.2-2
opensusebackports_sle
opensuseleap

Detection & IOCsextracted from sources · hover to see the quote

urlopenpgp4fpr:
command-platformpluginpath <arbitrary_path>
  • Monitor for Kleopatra process launches that include '-platformpluginpath' on the command line, which can be used to side-load an arbitrary DLL via a crafted openpgp4fpr: URL.
  • Inspect URL handler registrations and browser/mail-client activity for openpgp4fpr: scheme invocations, as these can pass unsanitized command-line options to Kleopatra.
  • ·Vulnerability is fixed in Kleopatra 3.1.12 (and 20.07.80 or later); Debian packages resolved at version 4:20.08.2-2 across bookworm, bullseye, trixie, forky, and sid.
  • ·Despite being classified as remotely triggerable (via a crafted URL), Debian's tracker scopes the issue as 'local', meaning user interaction (clicking a malicious openpgp4fpr: link) is required.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.