Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1607

Опубликовано: 13 фев. 2015
Источник: redhat
CVSS2: 1.2

Описание

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnupgWill not fix
Red Hat Enterprise Linux 5gnupg2Will not fix
Red Hat Enterprise Linux 6gnupg2Will not fix
Red Hat Enterprise Linux 7gnupg2Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=1193009gnupg2: memcpy with overlapping ranges (keybox_search.c)

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

CVSS3: 5.5
nvd
около 6 лет назад

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

CVSS3: 5.5
debian
около 6 лет назад

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2 ...

github
больше 3 лет назад

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

suse-cvrf
около 10 лет назад

Security update for gpg2

1.2 Low

CVSS2