Back

HIGH

gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification

Published Jun 8, 2018

Description

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having a security impact of Important, and a future update may address this flaw.

Red Hat mitigation

This flaw can be mitigated by appending the --no-verbose command line flag.

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 8, 2018
Updated Aug 5, 2024
Reserved Jun 7, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 8, 2018
ENISA EUVD
Assigner mitre
Published Jun 8, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-4011