It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).
- python python-gnupg 0.4.3
- python python-gnupg 0.3.6
- python python-gnupg 0.3.5
- python python-gnupg 0.3.4
Users should upgrade to 0.4.4
- docker pull avfisherdocker/python-gnupg0.4.3:CVE-2019-6690
- docker run -d -p 5000:5000 avfisherdocker/python-gnupg0.4.3:CVE-2019-6690
apt install libmojolicious-perl
git clone https://github.com/brianwrf/CVE-2019-6690
cd CVE-2019-6690
perl exploit.pl <ip> <port>