cbcvebase.
CVE-2020-8945
published 2020-02-12

CVE-2020-8945: The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This…

PriorityP343high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
5.07%
91.4th percentile
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiangolang-github-proglottis-gpgme< golang-github-proglottis-gpgme 0.1.1-1 (bookworm)golang-github-proglottis-gpgme 0.1.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
github.comproglottis_gpgme>= 0 < 0.1.10.1.1
gpgme_projectgpgme< 0.1.10.1.1
podman_projectpodman
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.