Cryptographic issues in GnuPG - CVE-2013-4351

 

Cryptographic issues in GnuPG - CVE-2013-4351

Published: October 10, 2013 / Updated: August 3, 2020


Vulnerability identifier: #VU33303
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4351
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.


Affected software

GnuPG
Gentoo Linux
gnupg (Alpine package)
dev-libs/libgcrypt
app-crypt/gnupg

How to mitigate CVE-2013-4351

Install update from vendor's website.

GnuPG - update to 1.4.0
gnupg (Alpine package) - update to 2.0.22-r0
dev-libs/libgcrypt - update to 1.5.3
app-crypt/gnupg - update to 2.0.22

External References

Related Security Bulletins