Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 740572 - <app-crypt/gnupg-2.2.23: AEAD preference list overflow (CVE-2020-25125)
Summary: <app-crypt/gnupg-2.2.23: AEAD preference list overflow (CVE-2020-25125)
Status: RESOLVED DUPLICATE of bug 740240
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [stable cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-09-05 19:49 UTC by GLSAMaker/CVETool Bot
Modified: 2020-09-05 19:51 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2020-09-05 19:49:23 UTC
CVE-2020-25125 (https://nvd.nist.gov/vuln/detail/CVE-2020-25125):
  GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading
  to a crash or possibly unspecified other impact, when a victim imports an
  attacker's OpenPGP key, and this key has AEAD preferences. The overflow is
  caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG
  2.2.23 is a fixed version.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-09-05 19:51:19 UTC

*** This bug has been marked as a duplicate of bug 740240 ***