Cryptographic issues in LibTMCG - #VU20321

 

Cryptographic issues in LibTMCG - #VU20321

Published: August 19, 2019


Vulnerability identifier: #VU20321
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass certain security restrictions.

The vulnerability exists due to unknown error, related to processing signatures in OpenPGP implementation.

Affected software

LibTMCG
Opensuse

Remediation

Install updates from vendor's website.

LibTMCG - update to 1.3.18

External References

Related Security Bulletins