PT-2006-7571 · Gnu+1 · Gnupg+1

Tavis Ormandy

·

Publicado

1970-01-01

·

Atualizado

2018-10-17

·

CVE-2006-6235

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GnuPG versions 1.x before 1.4.6 GnuPG versions 2.x before 2.0.2 GnuPG versions 1.9.0 through 1.9.95
Description The issue concerns multiple vulnerabilities in the gpg package that can lead to breaches in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerability in GnuPG allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
Recommendations For GnuPG versions 1.x before 1.4.6, update to version 1.4.6 or later. For GnuPG versions 2.x before 2.0.2, update to version 2.0.2 or later. For GnuPG versions 1.9.0 through 1.9.95, update to a version outside of this range, such as version 1.4.6 or later, or version 2.0.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-04219
BDU:2015-04952
BDU:2015-04953
CVE-2006-6235
DSA-1231-1
RHSA-2006:0754
RHSA-2006_0754

Produtos afetados

Gnupg
Red Hat