CVE-2013-4351

Description

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey.

Risk Information

Base Score
5.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
1.303

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0Windows
Vulnerabilities CVE-2007-1263,CVE-2013-4351,CVE-2013-4576 are affected in GnuPG for windows 1.4.6Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.1Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.13Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.14Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.15Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.16Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.6Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.7Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.2Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.17Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.18Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.19Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.13Windows
Vulnerabilities CVE-2013-4351,CVE-2014-9087 are affected in GnuPG for windows 2.1.0Windows
gnupg2 security update(DSA-2968-1) gnupg2_2.0.19-2+deb7u2_i386.debLinux
gnupg2 security update(DSA-2968-1) gnupg2_2.0.19-2+deb7u2_amd64.debLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.i386.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.x86_64.rpmLinux
CVE-2013-4351NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234