Cryptographic issues in GnuPG - CVE-2013-4351

 

Cryptographic issues in GnuPG - CVE-2013-4351

Published: October 10, 2013 / Updated: August 3, 2020


Vulnerability identifier: #VU33303
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-4351
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: GNU
Affected software:
GnuPG

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.


How to mitigate CVE-2013-4351

Install update from vendor's website.

Sources