PT-2014-5398 · Gnupg+3 · Gpgme+3

Published

2014-08-01

·

Updated

2023-02-13

·

CVE-2014-3564

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GPGME versions prior to 1.5.1
Description The issue is related to multiple heap-based buffer overflows in the status handler function, specifically in the engine-gpgsm.c and engine-uiserver.c files. This can be exploited by remote attackers to cause a denial of service, potentially leading to the execution of arbitrary code. The exploitation vectors are related to different line lengths in a specific order.
Recommendations For versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the status handler function in the affected files until a patch is applied.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1991
ALT-PU-2015-1727
CVE-2014-3564
DLA-39-1
DSA-3005-1
MGASA-2014-0340
OPENSUSE-SU-2024:10466-1
SUSE-SU-2014_1073-1
USN-2307-1

Affected Products

Alt Linux
Gpgme
Suse
Ubuntu