#VU25501 Use-after-free in gpgme - CVE-2020-8945

 

#VU25501 Use-after-free in gpgme - CVE-2020-8945

Published: February 21, 2020 / Updated: March 17, 2020


Vulnerability identifier: #VU25501
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-8945
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
gpgme
Software vendor:
James Fargher

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error, as demonstrated by use for container image pulls by Docker or CRI-O. A remote attacker can crash the target system, or cause potential code execution for Go applications that use this library under certain conditions during GPG signature verification.


Remediation

Install updates from vendor's website.

External links