Vulnerability Description
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Canonical | Ubuntu Linux | 12.04 |
| Debian | Debian Linux | 8.0 |
| Gnupg | Gnupg | < 2.2.8 |
Related Weaknesses (CWE)
References
- http://openwall.com/lists/oss-security/2018/06/08/2Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.htmlThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Apr/38Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/30/4Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/104450Broken Link
- http://www.securitytracker.com/id/1041051Broken Link
- https://access.redhat.com/errata/RHSA-2018:2180Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2181Third Party Advisory
- https://dev.gnupg.org/T4012PatchVendor Advisory
- https://github.com/RUB-NDS/Johnny-You-Are-FiredTechnical DescriptionThird Party Advisory
- https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pTechnical DescriptionThird Party Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxurThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlMailing ListThird Party Advisory
- https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000425.htmlMailing ListVendor Advisory
- https://usn.ubuntu.com/3675-1/Third Party Advisory
FAQ
What is CVE-2018-12020?
CVE-2018-12020 is a vulnerability with a CVSS score of 7.5 (HIGH). mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to...
How severe is CVE-2018-12020?
CVE-2018-12020 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12020?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Server Eus, Redhat Enterprise Linux Server Tus.