Description
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
References (35)
Core 35
Core References
Vendor Advisory vendor-advisory
x_refsource_trustix
http://www.trustix.org/errata/2006/0070
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017349
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23269
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23303
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453723/100/0/threaded
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23255
Patch vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-393-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23513
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23284
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-393-2
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23245
Various Sources mailing-list
x_refsource_mlist
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000491.html
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/427009
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_28_sr.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0754.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2006/dsa-1231
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453664/100/0/threaded
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23335
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23299
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/21462
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23329
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-03.xml
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23259
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2006:228
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23290
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-835
Various Sources vendor-advisory
x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.html
Vendor Advisory x_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2007-047.htm
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4881
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11245
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/23250
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.asc
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30711
Vendor Advisory vendor-advisory
x_refsource_openpkg
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24047
Scores
EPSS
0.0890
EPSS Percentile
92.7%
Details
Status
published
Products (30)
gnu/privacy_guard
1.2.4
gnu/privacy_guard
1.2.5
gnu/privacy_guard
1.2.6
gnu/privacy_guard
1.2.7
gnu/privacy_guard
1.3.3
gnu/privacy_guard
1.3.4
gnu/privacy_guard
1.4
gnu/privacy_guard
1.4.1
gnu/privacy_guard
1.4.2
gnu/privacy_guard
1.4.2.1
... and 20 more
Published
Dec 07, 2006
Tracked Since
Feb 18, 2026