CVE-2020-24972

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2020
Last modified:
07/11/2023

Description

The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kleopatra_project:kleopatra:*:*:*:*:*:gnupg:*:* 20.07.80 (excluding)
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*