Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-2180

Опубликовано: 11 июл. 2018
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2018-2180: gnupg2 security update (IMPORTANT)

[2.0.14-9]

  • fix CVE-2018-12020 - missing sanitization of original filename

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

gnupg2

2.0.14-9.el6_10

gnupg2-smime

2.0.14-9.el6_10

Oracle Linux i686

gnupg2

2.0.14-9.el6_10

gnupg2-smime

2.0.14-9.el6_10

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.

CVSS3: 7.5
redhat
больше 7 лет назад

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.

CVSS3: 7.5
nvd
больше 7 лет назад

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.

CVSS3: 7.5
debian
больше 7 лет назад

mainproc.c in GnuPG before 2.2.8 mishandles the original filename duri ...

suse-cvrf
больше 7 лет назад

Security update for gpg2