Lucene search

K
f5F5F5:K55121327
HistorySep 04, 2018 - 12:00 a.m.

K55121327 : GnuPG vulnerability CVE-2018-12020

2018-09-0400:00:00
my.f5.com
24

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%

Security Advisory Description

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the “–status-fd 2” option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes. (CVE-2018-12020)

Impact

There is no impact; F5 products are not affected by this vulnerability.