{"id":"CVE-2020-25125","details":"GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.","modified":"2026-07-08T05:56:18.669854685Z","published":"2020-09-03T18:15:15.160Z","related":["CGA-w8m2-q2wr-48v4","openSUSE-SU-2024:10815-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:gnupg:gnupg:2.2.21:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg:2.2.22:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.2.21"},{"last_affected":"2.2.21"},{"introduced":"2.2.22"},{"last_affected":"2.2.22"}],"source":"CPE_STRING","vendor_product":"gnupg:gnupg"}]},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/09/03/4"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/09/03/5"},{"type":"ADVISORY","url":"https://lists.gnupg.org/pipermail/gnupg-announce/2020q3/000448.html"},{"type":"REPORT","url":"https://bugzilla.opensuse.org/show_bug.cgi?id=1176034"},{"type":"FIX","url":"https://dev.gnupg.org/rG8ec9573e57866dda5efb4677d4454161517484bc"},{"type":"ARTICLE","url":"https://dev.gnupg.org/T5050"}],"affected":[{"ranges":[{"type":"GIT","repo":"git://git.gnupg.org/gpg4win.git","events":[{"introduced":"69077578c9cf52633e91b3cce5805fdedd643cc8"},{"last_affected":"69077578c9cf52633e91b3cce5805fdedd643cc8"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:gpg4win:gpg4win:3.1.12:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.1.12"},{"last_affected":"3.1.12"}]}}],"versions":["3.1.12","gpg4win-3.1.12"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25125.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}