Back to search
CVE-2020-25125
Published: Sep 3, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.opensuse.org/show_bug.cgi?id=1176034
x_refsource_MISC
https://dev.gnupg.org/rG8ec9573e57866dda5efb4677d4454161517484bc
x_refsource_MISC
https://dev.gnupg.org/T5050
x_refsource_MISC
[oss-security] 20200903 GNUPG released with AEAD sec fix CVE-2020-25125
mailing-list
x_refsource_MLIST
[oss-security] 20200903 CVE-2020-25125: gnupg2: buffer overflow when importing a key with AEAD preferences
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now