Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3564

Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.029
EPSS Ranking 85.5%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2014-3564
  • Gnu » Gpgme » Version: N/A
    cpe:2.3:a:gnu:gpgme:-
  • Gnu » Gpgme » Version: 1.1.3
    cpe:2.3:a:gnu:gpgme:1.1.3
  • Gnu » Gpgme » Version: 1.1.4
    cpe:2.3:a:gnu:gpgme:1.1.4
  • Gnu » Gpgme » Version: 1.5.0
    cpe:2.3:a:gnu:gpgme:1.5.0
  • Canonical » Ubuntu Linux » Version: 10.04
    cpe:2.3:o:canonical:ubuntu_linux:10.04
  • Canonical » Ubuntu Linux » Version: 12.04
    cpe:2.3:o:canonical:ubuntu_linux:12.04
  • Debian » Debian Linux » Version: 6.0
    cpe:2.3:o:debian:debian_linux:6.0


Contact Us

Shodan ® - All rights reserved