Lucene search

K
ubuntuUbuntuUSN-3675-1
HistoryJun 11, 2018 - 12:00 a.m.

GnuPG vulnerabilities

2018-06-1100:00:00
ubuntu.com
39

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%

Releases

  • Ubuntu 18.04 ESM
  • Ubuntu 17.10
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • gnupg - GNU privacy guard - a free PGP replacement
  • gnupg2 - GNU privacy guard - a free PGP replacement

Details

Marcus Brinkmann discovered that during decryption or verification,
GnuPG did not properly filter out terminal sequences when reporting the
original filename. An attacker could use this to specially craft a file
that would cause an application parsing GnuPG output to incorrectly
interpret the status of the cryptographic operation reported by GnuPG.
(CVE-2018-12020)

Lance Vick discovered that GnuPG did not enforce configurations where
key certification required an offline primary Certify key. An attacker
with access to a signing subkey could generate certifications that
appeared to be valid. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-9234)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchgnupg< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchdirmngr< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchdirmngr-dbgsym< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgnupg-agent< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgnupg-l10n< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgnupg-utils< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgnupg-utils-dbgsym< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgnupg2< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgpg< 2.2.4-1ubuntu1.1UNKNOWN
Ubuntu18.04noarchgpg-agent< 2.2.4-1ubuntu1.1UNKNOWN
Rows per page:
1-10 of 651

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

8.2 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.5%