MGASA-2018-0292

Source
https://advisories.mageia.org/MGASA-2018-0292.html
Import Source
https://advisories.mageia.org/MGASA-2018-0292.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0292
Related
Published
2018-06-19T23:42:28Z
Modified
2018-06-19T23:06:46Z
Summary
Updated gnupg gnupg2 packages fix a security vulnerability
Details

Updated gnupg, gnupg2, and python-gnupg packages fix security vulnerability:

Marcus Brinkmann discovered that during decryption or verification, GnuPG did not properly filter out terminal sequences when reporting the original filename. An attacker could use this to specially craft a file that would cause an application parsing GnuPG output to incorrectly interpret the status of the cryptographic operation reported by GnuPG (CVE-2018-12020).

References
Credits

Affected packages