CVE-2013-4351: Medium severity gnupg 2 (gnu privacy guard) vulnerability

Published Sep 20, 2013
·
Updated

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

Other sources

GnuPG and GnuPG2 are found to have a flaw, where the key flags are misinterpreted, which could possibly lead to a breach of confidentiality or a mistaken identity verification. Key flags are the packets, that indicated the capabilities of the key, represented as binary flags. The issue is that if a key or subkey has this "key flags" subpacket attached with all bits cleared (off), GnuPG currently treats the key as having all bits set (on), though the thing to note is that the keys with this sort of marker are very rare in the wild. The risks are unlikely today, and they are not particularly dangerous, but the keyholder's stated intent of separating out keys by context of use is being ignored, so there is a window of vulnerability that should not be open.

References: http://seclists.org/oss-sec/2013/q3/599 https://bugs.gentoo.org/showbug.cgi?id=484836 https://bugzilla.novell.com/showbug.cgi?id=840510

Red Hat

Affected Software

30 affected components
gnupg GnuPG=1.4.0
gnupg GnuPG=1.4.2
gnupg GnuPG=1.4.3
gnupg GnuPG=1.4.4
gnupg GnuPG=1.4.5
gnupg GnuPG=1.4.6
gnupg GnuPG=1.4.8
gnupg GnuPG=1.4.10
gnupg GnuPG=1.4.11
gnupg GnuPG=1.4.12
gnupg GnuPG=1.4.13
gnupg GnuPG=2.0
gnupg GnuPG=2.0.1
gnupg GnuPG=2.0.3
gnupg GnuPG=2.0.4
gnupg GnuPG=2.0.5
gnupg GnuPG=2.0.6
gnupg GnuPG=2.0.7
gnupg GnuPG=2.0.8
gnupg GnuPG=2.0.10
gnupg GnuPG=2.0.11
gnupg GnuPG=2.0.12
gnupg GnuPG=2.0.13
gnupg GnuPG=2.0.14
gnupg GnuPG=2.0.15
gnupg GnuPG=2.0.16
gnupg GnuPG=2.0.17
gnupg GnuPG=2.0.18
gnupg GnuPG=2.0.19
gnupg GnuPG=2.1.0-beta1

Event History

Sep 20, 2013
Data Sourced
05:20 AM
DescriptionSeverityAffected Software
Oct 10, 2013
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-4351?

The severity of CVE-2013-4351 is classified as moderate, as it can potentially allow unauthorized use of cryptographic protections.

2

How do I fix CVE-2013-4351?

To fix CVE-2013-4351, update GnuPG to a version that addresses the issue, specifically version 1.4.14 or later for GnuPG 1.4.x and version 2.0.20 or later for GnuPG 2.0.x.

3

Which versions are affected by CVE-2013-4351?

CVE-2013-4351 affects GnuPG versions 1.4.0 through 1.4.13 and 2.0.0 through 2.0.19.

4

Can CVE-2013-4351 lead to data compromise?

Yes, CVE-2013-4351 can lead to data compromise by allowing attackers to misuse cryptographic keys.

5

Is CVE-2013-4351 related to key management?

Yes, CVE-2013-4351 specifically involves a vulnerability in how GnuPG handles key flags, impacting key management.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203