PT-2006-7570 · Gnu+1 · Gnupg+1

Werner Koch

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2006-6169

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GnuPG versions 1.4 and 2.0
Description The issue is related to multiple vulnerabilities in the GnuPG package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a heap-based buffer overflow in the ask outfile name function in openfile.c for GnuPG, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions.
Recommendations For GnuPG versions 1.4 and 2.0, consider disabling the ask outfile name function in openfile.c to minimize the risk of exploitation until a patch is available. Restrict access to the make printable string function to prevent attackers from executing arbitrary code.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04219
BDU:2015-04952
BDU:2015-04953
CVE-2006-6169
DSA-1231-1
OPENSUSE-SU-2024:10815-1
RHSA-2006:0754
RHSA-2006_0754

Affected Products

Gnupg
Red Hat