CVE-2012-6085: Input Validation

Published Jan 2, 2013
·
Updated

KB Sriram (kbsriram) reports:

Versions of GnuPG <= 1.4.12 are vulnerable to memory access violations and public keyring database corruption when importing public keys that have been manipulated.

An OpenPGP key can be fuzzed in such a way that gpg segfaults (or has other memory access violations) when importing the key.

The key may also be fuzzed such that gpg reports no errors when examining the key (eg: "gpg thebadkey.pkr") but importing it causes gpg to corrupt its public keyring database.

The database corruption issue was first reported on Dec 6th, through the gpg bug tracking system:

https://bugs.g10code.com/gnupg/issue1455

The subsequent memory access violation was discovered and reported in a private email with the maintainer on Dec 20th.

A zip file with keys that causes segfaults and other errors is available at http://dl.dropbox.com/u/18852638/gnupg-issues/1455.zip and includes a log file that demonstrates the issues [on MacOS X and gpg 1.4.11]

A new version of gpg -- 1.4.13 -- that addressed both these issues, was independently released by the maintainer on Dec 20th.

The simplest solution is to upgrade all gpg installs to 1.4.13.

[Workarounds: A corrupted database may be recovered by manually copying back the pubring.gpg~ backup file. Certain errors may also be prevented by never directly importing a key, but first just "looking" at the key (eg: "gpg badkey.pkr"). However, this is not guaranteed to work in all cases; though upgrading to 1.4.13 does work for the issues reported.]

Discovery:

The problem was discovered during a byte-fuzzing test of OpenPGP certificates for an unrelated application. Each byte in turn was replaced by a random byte, and the modified certificate fed to the application to check that it handled errors correctly. Gpg was used as a control, but it itself turned out to have errors related to packet parsing. The errors are generally triggered when fuzzing the length field of OpenPGP packets, which cascades into subsequent errors in certain situations.

External references: https://bugs.g10code.com/gnupg/issue1455 http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commitdiff;h=f0b33b6fb8e0586e9584a7a409dcc31263776a67

Other sources

The readblock function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

MITRE

Affected Software

27 affected components
gnupg GnuPG=1.4.0
gnupg GnuPG=1.4.2
gnupg GnuPG=1.4.3
gnupg GnuPG=1.4.4
gnupg GnuPG=1.4.5
gnupg GnuPG=1.4.8
gnupg GnuPG=1.4.10
gnupg GnuPG=1.4.11
gnupg GnuPG=1.4.12
gnupg GnuPG=2.0
gnupg GnuPG=2.0.1
gnupg GnuPG=2.0.3
gnupg GnuPG=2.0.4
gnupg GnuPG=2.0.5
gnupg GnuPG=2.0.6
gnupg GnuPG=2.0.7
gnupg GnuPG=2.0.8
gnupg GnuPG=2.0.10
gnupg GnuPG=2.0.11
gnupg GnuPG=2.0.12
gnupg GnuPG=2.0.13
gnupg GnuPG=2.0.14
gnupg GnuPG=2.0.15
gnupg GnuPG=2.0.16
gnupg GnuPG=2.0.17
gnupg GnuPG=2.0.18
gnupg GnuPG=2.0.19

Event History

Jan 2, 2013
Data Sourced
via Red Hat·01:30 AM
DescriptionSeverityAffected Software
Jan 24, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2012-6085?

CVE-2012-6085 has a medium severity due to memory access violations and potential database corruption.

2

How do I fix CVE-2012-6085?

To fix CVE-2012-6085, upgrade GnuPG to version 1.4.13 or later.

3

What versions of GnuPG are affected by CVE-2012-6085?

Versions of GnuPG up to and including 1.4.12 are affected by CVE-2012-6085.

4

What are the consequences of CVE-2012-6085?

Exploitation of CVE-2012-6085 can lead to application crashes and corruption of the public keyring database.

5

Is CVE-2012-6085 still relevant?

Although CVE-2012-6085 was identified over a decade ago, it remains important for users running vulnerable versions of GnuPG.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203