PT-2013-1172 · Gnu+3 · Gnupg+3

Kb Sriram

+1

·

Published

2013-01-24

·

Updated

2023-02-13

·

CVE-2012-6085

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GnuPG versions 1.4.x through 1.4.12 GnuPG versions 2.0.x through 2.0.19 gnupg2 versions 2.0.10 through 2.0.14
Description The issue affects the integrity and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The read block function in g10/import.c, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.
Recommendations For GnuPG versions 1.4.x through 1.4.12, update to version 1.4.13 or later. For GnuPG versions 2.0.x through 2.0.19, update to version 2.0.20 or later. For gnupg2 versions 2.0.10 through 2.0.14, update to a version later than 2.0.14. As a temporary workaround, consider restricting the use of the read block function in g10/import.c until a patch is available.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

BDU:2015-06662
BDU:2015-06663
BDU:2015-06664
BDU:2015-06665
BDU:2015-06666
BDU:2015-08927
BDU:2015-08928
BDU:2015-08929
BDU:2015-08930
BDU:2015-08931
CESA-2013_1459
CVE-2012-6085
DSA-2601-1
RHSA-2013:1458
RHSA-2013:1459
RHSA-2013_1458
RHSA-2013_1459
SUSE-SU-2013_1058-1
SUSE-SU-2013_1058-2
SUSE-SU-2013_1061-1
SUSE-SU-2013_1577-1

Affected Products

Centos
Gnupg
Red Hat
Suse