VDB
Sign up
HIGH7.5

GHSA-m6wg-2mwg-4rfq

GPGME Go wrapper contains Use After Free

Quick fix

GHSA-m6wg-2mwg-4rfq — github.com/proglottis/gpgme: upgrade to the fixed version with the command below.

go get github.com/proglottis/gpgme@v0.1.1

Details

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/proglottis/gpgme
Introduced in: 0Fixed in: 0.1.1
Fixgo get github.com/proglottis/gpgme@v0.1.1

References