CVE-2020-24972
published 2020-08-29CVE-2020-24972: The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kleopatra | < kleopatra 4:20.08.2-2 (bookworm) | kleopatra 4:20.08.2-2 (bookworm) |
| fedoraproject | fedora | — | — |
| kleopatra_project | kleopatra | < 20.07.80 | 20.07.80 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| kleopatra_project | kleopatra | >= 0 < 4:20.08.2-2 | 4:20.08.2-2 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH