PT-2014-9096 · Gnu+4 · Gnupg+4

Florian Maury

+2

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2014-4617

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 1.4.17 GnuPG versions prior to 2.0.24 GnuPG2 (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the GnuPG package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, the do uncompress function in g10/compress.c allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets.
Recommendations For GnuPG versions prior to 1.4.17, update to version 1.4.17 or later to resolve the issue. For GnuPG versions prior to 2.0.24, update to version 2.0.24 or later to resolve the issue. For GnuPG2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1852
ALT-PU-2014-1874
BDU:2015-02001
BDU:2015-02002
CVE-2014-4617
DLA-0012-1
DLA-51-1
DSA-2967-1
DSA-2968-1
MGASA-2014-0276
OPENSUSE-SU-2024:10102-1
SUSE-SU-2014_0896-1
USN-2258-1

Produtos afetados

Alt Linux
Debian
Gnupg
Suse
Ubuntu