Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3219

Опубликовано: 15 сент. 2022
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gnupg2Out of support scope
Red Hat Enterprise Linux 7gnupg2Out of support scope
Red Hat Enterprise Linux 8gnupg2Fix deferred
Red Hat Enterprise Linux 9gnupg2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2127010gnupg: denial of service issue (resource consumption) using compressed packets

EPSS

Процентиль: 22%
0.00293
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 3 лет назад

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

CVSS3: 3.3
nvd
больше 3 лет назад

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

CVSS3: 3.3
debian
больше 3 лет назад

GnuPG can be made to spin on a relatively small input by (for example) ...

CVSS3: 5.5
github
больше 3 лет назад

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

CVSS3: 3.3
fstec
больше 4 лет назад

Уязвимость программы для шифрования информации и создания электронных цифровых подписей GnuPG, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00293
Низкий

6.2 Medium

CVSS3