#VU25501 Use-after-free in gpgme - CVE-2020-8945
Published: February 21, 2020 / Updated: March 17, 2020
gpgme
James Fargher
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error, as demonstrated by use for container image pulls by Docker or CRI-O. A remote attacker can crash the target system, or cause potential code execution for Go applications that use this library under certain conditions during GPG signature verification.