ZeroHour

CVE-2020-8945

PoC
CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Vendors
gpgme projectredhatfedoraproject
Products
gpgme, openshift container platform, openshift container platform for ibm z, openshift container platform for linuxone, fedora, enterprise linux for ibm z systems, enterprise linux for power little endian, enterprise linux server, enterprise linux workstation
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.