1 results (0.003 seconds)

CVSS: 8.8EPSS: 21%CPEs: 4EXPL: 2

29 Aug 2020 — The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL. El componente Kleopatra versiones anteriores a 3.1.12 (y versiones anteriores a 20.07.80) para GnuPG, permite a atacantes remotos ejecutar código arbitrario porque las URL openpgp4fpr: son compatibles sin un manejo seguro... • https://github.com/SpiralBL0CK/CVE-2020-24972 • CWE-116: Improper Encoding or Escaping of Output •