CVE-2019-6690

python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended (CVE-2019-6690)

Description

python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
94.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
8.6 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2019-03-17 17:02 UTC

Affected operating systems

  • linux

    debian / debian_linux8.0

  • linux

    debian / debian_linux9.0

  • linux

    opensuse / leap15.0

  • linux

    canonical / ubuntu_linux18.04

  • linux

    canonical / ubuntu_linux18.10

  • linux

    canonical / ubuntu_linux19.04

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • python

    python-gnupg

  • suse

    backports

References & sources

IDCVE-2019-6690