Back

HIGH

python-gnupg: improper input validation in gnupg.GPG.encrypt() and gnupg.GPG.decrypt()

Published Mar 17, 2019

Description

python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.

Affected products

Remediation

Red Hat statement

The issue affects the versions of python-gnupg shipped with Red Hat Update Infrastructure 3, however the vulnerable functions are never used by the product. The issue affects the versions of python-gnupg shipped with Red Hat Satellite 6, however the vulnerable functions are never used by the product.

Red Hat mitigation

Filter out newlines from passphrases before passing them to python-gnupg.

Metrics

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 17, 2019
Updated Aug 4, 2024
Reserved Jan 23, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 23, 2019
GHSA-2FCH-JVG5-CRF6