CVE-2013-4351
Summary
| CVE | CVE-2013-4351 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-10 00:55:15 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted), which might allow remote attackers to bypass intended cryptographic protection mechanisms by leveraging the subkey. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnupg | Gnupg | 1.4.0 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.10 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.11 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.12 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.13 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.2 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.3 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.4 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.5 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.6 | All | All | All |
| Application | Gnupg | Gnupg | 1.4.8 | All | All | All |
| Application | Gnupg | Gnupg | 2.0 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.1 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.10 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.11 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.12 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.13 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.14 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.15 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.16 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.17 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.18 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.19 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.3 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.4 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.5 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.6 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.7 | All | All | All |
| Application | Gnupg | Gnupg | 2.0.8 | All | All | All |
| Application | Gnupg | Gnupg | 2.1.0 | beta1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1010137 – (CVE-2013-4351) CVE-2013-4351 gnupg: treats no-usage-permitted keys as all-usages-permitted | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Debian -- Security Information -- DSA-2773-1 gnupg | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| oss-security - Re: GnuPG treats no-usage-permitted keys as all-usages-permitted | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| openSUSE-SU-2013:1532-1: moderate: update for gpg2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2774-1 gnupg2 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| thread.gmane.org | 522: Connection timed out | af854a3a-2127-422b-91ae-364da2661108 | thread.gmane.org | |
| openSUSE-SU-2013:1526-1: moderate: update for gpg2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-1987-1: GnuPG vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.