Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-2547

Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.151
EPSS Ranking 94.2%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 5.1
References
Products affected by CVE-2010-2547
  • Gnupg » Gnupg » Version: 2.0.0
    cpe:2.3:a:gnupg:gnupg:2.0.0
  • Gnupg » Gnupg » Version: 2.0.1
    cpe:2.3:a:gnupg:gnupg:2.0.1
  • Gnupg » Gnupg » Version: 2.0.10
    cpe:2.3:a:gnupg:gnupg:2.0.10
  • Gnupg » Gnupg » Version: 2.0.11
    cpe:2.3:a:gnupg:gnupg:2.0.11
  • Gnupg » Gnupg » Version: 2.0.12
    cpe:2.3:a:gnupg:gnupg:2.0.12
  • Gnupg » Gnupg » Version: 2.0.13
    cpe:2.3:a:gnupg:gnupg:2.0.13
  • Gnupg » Gnupg » Version: 2.0.14
    cpe:2.3:a:gnupg:gnupg:2.0.14
  • Gnupg » Gnupg » Version: 2.0.15
    cpe:2.3:a:gnupg:gnupg:2.0.15
  • Gnupg » Gnupg » Version: 2.0.16
    cpe:2.3:a:gnupg:gnupg:2.0.16
  • Gnupg » Gnupg » Version: 2.0.2
    cpe:2.3:a:gnupg:gnupg:2.0.2
  • Gnupg » Gnupg » Version: 2.0.3
    cpe:2.3:a:gnupg:gnupg:2.0.3
  • Gnupg » Gnupg » Version: 2.0.4
    cpe:2.3:a:gnupg:gnupg:2.0.4
  • Gnupg » Gnupg » Version: 2.0.5
    cpe:2.3:a:gnupg:gnupg:2.0.5
  • Gnupg » Gnupg » Version: 2.0.6
    cpe:2.3:a:gnupg:gnupg:2.0.6
  • Gnupg » Gnupg » Version: 2.0.7
    cpe:2.3:a:gnupg:gnupg:2.0.7
  • Gnupg » Gnupg » Version: 2.0.8
    cpe:2.3:a:gnupg:gnupg:2.0.8
  • Gnupg » Gnupg » Version: 2.0.9
    cpe:2.3:a:gnupg:gnupg:2.0.9
  • Debian » Debian Linux » Version: 5.0
    cpe:2.3:o:debian:debian_linux:5.0
  • Fedoraproject » Fedora » Version: 13
    cpe:2.3:o:fedoraproject:fedora:13


Contact Us

Shodan ® - All rights reserved