VYPR
High severity7.5NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026

CVE-2020-8945

CVE-2020-8945

Description

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/proglottis/gpgmeGo
< 0.1.10.1.1

Affected products

20
  • cpe:2.3:a:gpgme_project:gpgme:*:*:*:*:*:go:*:*
    Range: <0.1.1
  • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.5:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.2:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.2:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
  • proglottis/GPGME librarydescription

Patches

Vulnerability mechanics

References

19

News mentions

0

No linked articles in our index yet.