Marcus Brinkmann discovered that during decryption or verification, GnuPG did not properly filter out terminal sequences when reporting the original filename. An attacker could use this to specially craft a file that would cause an application parsing GnuPG output to incorrectly interpret the status of the cryptographic operation reported by GnuPG. (CVE-2018-12020)
Lance Vick discovered that GnuPG did not enforce configurations where key certification required an offline primary Certify key. An attacker with access to a signing subkey could generate certifications that appeared to be valid. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-9234)
{ "availability": "No subscription required", "binaries": [ { "binary_name": "gnupg", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gnupg-curl", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gnupg-curl-dbgsym", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gnupg-dbgsym", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gnupg-udeb", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gnupg-udeb-dbgsym", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gpgv", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gpgv-dbgsym", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gpgv-udeb", "binary_version": "1.4.16-1ubuntu2.5" }, { "binary_name": "gpgv-udeb-dbgsym", "binary_version": "1.4.16-1ubuntu2.5" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "gnupg", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gnupg-curl", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gnupg-curl-dbgsym", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gnupg-dbg", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gnupg-dbgsym", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gpgv", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gpgv-dbgsym", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gpgv-udeb", "binary_version": "1.4.20-1ubuntu3.2" }, { "binary_name": "gpgv-udeb-dbgsym", "binary_version": "1.4.20-1ubuntu3.2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "dirmngr", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "dirmngr-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg-agent", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg-l10n", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg-utils", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg-utils-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gnupg2", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-agent", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-agent-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-wks-client", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-wks-client-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-wks-server", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpg-wks-server-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgconf", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgconf-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgsm", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgsm-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv-static", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv-static-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv-udeb", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv-win32", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "gpgv2", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "scdaemon", "binary_version": "2.2.4-1ubuntu1.1" }, { "binary_name": "scdaemon-dbgsym", "binary_version": "2.2.4-1ubuntu1.1" } ] }