7.5

CVE-2020-8945

Exploit
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gpgme Project ≫ Gpgme SwPlatform go Version < 0.1.1
Redhat ≫ Openshift Container Platform Version 3.11
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.1
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.2
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.3
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.4
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform Version 4.5
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.1
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform For Ibm Z Version 4.2
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform For Linuxone Version 4.1
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Openshift Container Platform For Linuxone Version 4.2
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.07% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://access.redhat.com/errata/RHSA-2020:0679
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0689
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0697
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1795838
Patch
Third Party Advisory
Issue Tracking
https://github.com/containers/image/commit/4c7a23f82ef09127b0ff28366d1cf31316dd6cc1
Patch
Third Party Advisory
https://github.com/proglottis/gpgme/compare/v0.1.0...v0.1.1
Patch
Third Party Advisory
https://github.com/proglottis/gpgme/pull/23
Patch
Third Party Advisory
Exploit
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H6P6SSNKN4H6GSEVROHBDXA64PX7EOED/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KDBT77KV3U7BESJX3P4S4MPVDGRTAQA2/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXV7NZELYWRRCXATXU3FYD3G3WJT3WYM/