DEBIAN-CVE-2018-12020

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2018-12020
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2018-12020.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2018-12020
Upstream
Published
2018-06-08T21:29:00Z
Modified
2025-09-19T06:06:46Z
Summary
[none]
Details

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP data might represent an original filename that contains line feed characters in conjunction with GOODSIG or VALIDSIG status codes.

References

Affected packages

Debian:11

enigmail

Package

Name
enigmail
Purl
pkg:deb/debian/enigmail?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:2.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

gnupg1

Package

Name
gnupg1
Purl
pkg:deb/debian/gnupg1?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.22-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.8-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

gnupg1

Package

Name
gnupg1
Purl
pkg:deb/debian/gnupg1?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.22-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.8-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

gnupg1

Package

Name
gnupg1
Purl
pkg:deb/debian/gnupg1?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.22-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.8-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

gnupg1

Package

Name
gnupg1
Purl
pkg:deb/debian/gnupg1?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.22-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

gnupg2

Package

Name
gnupg2
Purl
pkg:deb/debian/gnupg2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.8-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}