gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification
Published Jun 8, 2018
7.5
HIGHCVSS 3.1
EPSS 8.55%
Description
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Affected products
No data.
Configuration 1
- 6.0
- 7.0
- 6.0
- 7.0
- 7.6
- 7.5
- 7.6
- 7.6
- 6.0
- 7.0
Configuration 2
- 12.04
- 14.04
- 16.04
- 17.10
- 18.04
- 18.10
- 19.04
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 6
gnupg2-0:2.0.14-9.el6_10
Fixed · RHSA-2018:2180
Red Hat Enterprise Linux 7
gnupg2-0:2.0.22-5.el7_5
Fixed · RHSA-2018:2181
Red Hat Enterprise Linux 5
gnupg
Will not fix
Red Hat Enterprise Linux 5
gnupg2
Will not fix
Red Hat Enterprise Linux 8
gnupg2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | gnupg2-0:2.0.14-9.el6_10 | Fixed | RHSA-2018:2180 |
| Red Hat Enterprise Linux 7 | gnupg2-0:2.0.22-5.el7_5 | Fixed | RHSA-2018:2181 |
| Red Hat Enterprise Linux 5 | gnupg | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | gnupg2 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | gnupg2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having a security impact of Important, and a future update may address this flaw.
Red Hat mitigation
This flaw can be mitigated by appending the --no-verbose command line flag.
References (26)
- http://openwall.com/lists/oss-security/2018/06/08/2 x_refsource_MISCMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/38 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/30/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/104450 vdb-entryx_refsource_BIDBroken Link
- http://www.securitytracker.com/id/1041051 vdb-entryx_refsource_SECTRACKBroken Link
- https://access.redhat.com/errata/RHSA-2018:2180 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2181 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-12020 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1589620 Issue Tracking
- https://dev.gnupg.org/T4012 x_refsource_MISCPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-4011 Advisory
- https://github.com/RUB-NDS/Johnny-You-Are-Fired x_refsource_MISCTechnical DescriptionThird Party Advisory
- https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf x_refsource_MISCTechnical DescriptionThird Party Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00027.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.html x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12020
- https://usn.ubuntu.com/3675-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3675-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3675-3/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3964-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-12020
- https://www.debian.org/security/2018/dsa-4222 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4223 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4224 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.