Created python-gnupg tracking bugs for this issue:
Affects: epel-6 [bug 1670367]
Affects: epel-7 [bug 1670368]
Affects: fedora-all [bug 1670366]
Comment 3Riccardo Schirone
2019-03-07 16:25:47 UTC
Mitigation:
Filter out newlines from passphrases before passing them to python-gnupg.
Comment 8Richard Maciel Costa
2019-04-25 03:48:09 UTC
Statement:
The issue affects the versions of python-gnupg shipped with Red Hat Update Infrastructure 3, however the vulnerable functions are never used by the product.
The issue affects the versions of python-gnupg shipped with Red Hat Satellite 6, however the vulnerable functions are never used by the product.
Comment 9Product Security DevOps Team
2021-01-20 11:59:13 UTC