PyPi: Python-Gnupg

CVE-2014-1928

Safety vulnerability ID: 52944

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Oct 25, 2014 Updated at Sep 21, 2024
Scan your Python projects for vulnerabilities →

Advisory

Python-gnupg 0.3.6 includes a fix for CVE-2014-1928: The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927.
NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.

Affected package

python-gnupg

Latest version: 0.5.3

A wrapper for the Gnu Privacy Guard (GPG or GnuPG)

Affected versions

Fixed versions

Vulnerability changelog

The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.


MLIST:[oss-security] 20140204 Re: CVE request: python-gnupg before 0.3.5 shell injection: http://seclists.org/oss-sec/2014/q1/245
MLIST:[oss-security] 20140209 Re: CVE request: python-gnupg before 0.3.5 shell injection: http://seclists.org/oss-sec/2014/q1/294
CONFIRM:https://code.google.com/p/python-gnupg/: https://code.google.com/p/python-gnupg/
CONFIRM:https://code.google.com/p/python-gnupg/issues/detail?id=98: https://code.google.com/p/python-gnupg/issues/detail?id=98
DEBIAN:DSA-2946: http://www.debian.org/security/2014/dsa-2946
SECUNIA:56616: http://secunia.com/advisories/56616
SECUNIA:59031: http://secunia.com/advisories/59031

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

MEDIUM 4.6

CVSS v2 Details

MEDIUM 4.6
Access Vector (AV)
LOCAL
Access Complexity (AC)
LOW
Authentication (Au)
NONE
Confidentiality Impact (C)
PARTIAL
Integrity Impact (I)
PARTIAL
Availability Impact (A)
PARTIAL