PT-2014-9096 · Gnu+4 · Gnupg+4

Florian Maury

+2

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-4617

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GnuPG versions prior to 1.4.17 GnuPG versions prior to 2.0.24 GnuPG2 (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the GnuPG package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. Specifically, the do uncompress function in g10/compress.c allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets.
Recommendations For GnuPG versions prior to 1.4.17, update to version 1.4.17 or later to resolve the issue. For GnuPG versions prior to 2.0.24, update to version 2.0.24 or later to resolve the issue. For GnuPG2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1852
ALT-PU-2014-1874
BDU:2015-02001
BDU:2015-02002
CVE-2014-4617
DLA-0012-1
DLA-51-1
DSA-2967-1
DSA-2968-1
MGASA-2014-0276
OPENSUSE-SU-2024:10102-1
SUSE-SU-2014_0896-1
USN-2258-1

Affected Products

Alt Linux
Debian
Gnupg
Suse
Ubuntu