Improper validation of certificate with host mismatch in SKS Keyserver and GnuPG - CVE-2019-13050

 

Improper validation of certificate with host mismatch in SKS Keyserver and GnuPG - CVE-2019-13050

Published: September 10, 2019


Vulnerability identifier: #VU20961
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13050
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a persistent denial of service (DoS) condition on the target system.

The vulnerability exists due to the interaction between the vulnerable applications makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. A remote attacker can retrieve data from this network and cause a persistent denial of service, because of a certificate spamming attack.

Affected software

SKS Keyserver
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
GnuPG
Migration Toolkit for Containers
Traffix SDC
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
gnupg (Ubuntu package)
gnupg2
gnupg2 (Red Hat package)
Platform Automation Toolkit

How to mitigate CVE-2019-13050

Install updates from vendor's website.

GnuPG - update to 2.2.17
Migration Toolkit for Containers - update to 1.7.3
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
gnupg (Ubuntu package) - update to 2.2.4-1ubuntu1.5
gnupg2 - addressed in versions 2.2.17-1.fc29, 2.2.17-1.fc30
gnupg2 (Red Hat package) - update to 2.2.20-2.el8
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.15, 2.13.7
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22

External References

Related Security Bulletins