Vulnerabilities
Vulnerable Software
Gnupg:  >> Gnupg  >> 1.4.16  Security Vulnerabilities
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
CVSS Score
5.0
EPSS Score
0.08
Published
2014-06-25
parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.
CVSS Score
5.0
EPSS Score
0.231
Published
2006-06-19


Contact Us

Shodan ® - All rights reserved