High severity7.5GHSA Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2019-6690
CVE-2019-6690
Description
python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
python-gnupgPyPI | < 0.4.4 | 0.4.4 |
Affected products
12- cpe:2.3:a:python:python-gnupg:0.4.3:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- ghsa-coords3 versionspkg:pypi/python-gnupgpkg:rpm/opensuse/python-python-gnupg&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-python-gnupg&distro=SUSE%20Package%20Hub%2015
< 0.4.4+ 2 more
- (no CPE)range: < 0.4.4
- (no CPE)range: < 0.5.2-1.5
- (no CPE)range: < 0.4.4-bp150.2.3.1
Patches
Vulnerability mechanics
References
21- lists.opensuse.org/opensuse-security-announce/2019-02/msg00008.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2019-02/msg00058.htmlnvdMailing ListThird Party AdvisoryWEB
- packetstormsecurity.com/files/151341/Python-GnuPG-0.4.3-Improper-Input-Validation.htmlnvdThird Party AdvisoryVDB EntryWEB
- blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability/nvdThird Party Advisory
- github.com/advisories/GHSA-2fch-jvg5-crf6ghsaADVISORY
- lists.debian.org/debian-lts-announce/2019/02/msg00021.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2021/12/msg00027.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-6690ghsaADVISORY
- pypi.org/project/python-gnupg/nvdProductThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Jan/41nvdMailing ListThird Party AdvisoryWEB
- usn.ubuntu.com/3964-1/nvdThird Party Advisory
- www.securityfocus.com/bid/106756nvdBroken Link
- blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerabilityghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7IIghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/X4VFRUG56542LTYK4444TPJBGR57MT25ghsaWEB
- usn.ubuntu.com/3964-1ghsaWEB
- web.archive.org/web/20200227091727/http://www.securityfocus.com/bid/106756ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7II/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X4VFRUG56542LTYK4444TPJBGR57MT25/nvd
News mentions
0No linked articles in our index yet.