PT-2006-7571 · Gnu+1 · Gnupg+1

Tavis Ormandy

·

Published

1970-01-01

·

Updated

2018-10-17

·

CVE-2006-6235

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GnuPG versions 1.x before 1.4.6 GnuPG versions 2.x before 2.0.2 GnuPG versions 1.9.0 through 1.9.95
Description The issue concerns multiple vulnerabilities in the gpg package that can lead to breaches in confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerability in GnuPG allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
Recommendations For GnuPG versions 1.x before 1.4.6, update to version 1.4.6 or later. For GnuPG versions 2.x before 2.0.2, update to version 2.0.2 or later. For GnuPG versions 1.9.0 through 1.9.95, update to a version outside of this range, such as version 1.4.6 or later, or version 2.0.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04219
BDU:2015-04952
BDU:2015-04953
CVE-2006-6235
DSA-1231-1
RHSA-2006:0754
RHSA-2006_0754

Affected Products

Gnupg
Red Hat