mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-06-08T21:00:00
Updated: 2024-08-05T08:24:03.773Z
Reserved: 2018-06-07T00:00:00
Link: CVE-2018-12020
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-08T21:29:00.237
Modified: 2024-11-21T03:44:25.510
Link: CVE-2018-12020
Redhat