Insecure DLL loading in kleopatra - CVE-2020-24972
Published: August 31, 2020
Vulnerability identifier: #VU46133
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24972
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to topenpgp4fpr: URLs are supported without safe handling of command-line options. A remote attacker can trick a victim to process a specially crafted URL via "openpgp4fpr" handler and execute arbitrary code on victim's system.
Affected software
kleopatra
Gentoo Linux
SUSE Linux
Opensuse
Fedora
kleopatra
Gentoo Linux
SUSE Linux
Opensuse
Fedora
kleopatra
How to mitigate CVE-2020-24972
Install updates from vendor's website.
kleopatra - update to 20.07.80
kleopatra - update to 19.12.2-2.fc32
kleopatra - update to 19.12.2-2.fc32