CVE-2020-24972: High severity kleopatra vulnerability
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-24972?
CVE-2020-24972 is a vulnerability in the Kleopatra component of GnuPG that allows remote attackers to execute arbitrary code.
How does CVE-2020-24972 work?
CVE-2020-24972 works by not safely handling command-line options for openpgp4fpr: URLs, allowing the Qt platformpluginpath command-line option to load an arbitrary DLL.
What is the severity of CVE-2020-24972?
CVE-2020-24972 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2020-24972?
Versions of Kleopatra before 3.1.12 and 20.07.80 for GnuPG are affected by CVE-2020-24972.
How can I fix CVE-2020-24972?
To fix CVE-2020-24972, it is recommended to update to version 3.1.12 or 20.07.80 of Kleopatra for GnuPG.