Improper validation of certificate with host mismatch in SKS Keyserver and GnuPG - CVE-2019-13050
Published: September 10, 2019
Vulnerability identifier: #VU20961
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13050
CWE-ID: CWE-297
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a persistent denial of service (DoS) condition on the target system.
The vulnerability exists due to the interaction between the vulnerable applications makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. A remote attacker can retrieve data from this network and cause a persistent denial of service, because of a certificate spamming attack.
Affected software
SKS Keyserver
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
GnuPG
Migration Toolkit for Containers
Traffix SDC
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
gnupg (Ubuntu package)
gnupg2
gnupg2 (Red Hat package)
Platform Automation Toolkit
Service Telemetry Framework
Isolation Segment
VMware Tanzu Application Service for VMs
GnuPG
Migration Toolkit for Containers
Traffix SDC
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
gnupg (Ubuntu package)
gnupg2
gnupg2 (Red Hat package)
Platform Automation Toolkit
How to mitigate CVE-2019-13050
Install updates from vendor's website.
GnuPG - update to 2.2.17
Migration Toolkit for Containers - update to 1.7.3
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
gnupg (Ubuntu package) - update to 2.2.4-1ubuntu1.5
gnupg2 - addressed in versions 2.2.17-1.fc29, 2.2.17-1.fc30
gnupg2 (Red Hat package) - update to 2.2.20-2.el8
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.15, 2.13.7
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
Migration Toolkit for Containers - update to 1.7.3
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
gnupg (Ubuntu package) - update to 2.2.4-1ubuntu1.5
gnupg2 - addressed in versions 2.2.17-1.fc29, 2.2.17-1.fc30
gnupg2 (Red Hat package) - update to 2.2.20-2.el8
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.10
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.15, 2.13.7
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
External References
Related Security Bulletins
- Denial of service in GnuPG
- Denial of service in F5 Networks Traffix SDC GnuPG component
- OpenSUSE Linux update for gpg2
- Red Hat Enterprise Linux 8 update for gnupg2
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Ubuntu update for gnupg2
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- VMware Tanzu products update for GnuPG
- Fedora 30 update for gnupg2
- Fedora 29 update for gnupg2