Описание
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.4.16-1.2ubuntu1 |
esm-infra-legacy/trusty | not-affected | 1.4.16-1ubuntu2.1 |
lucid | released | 1.4.10-2ubuntu1.6 |
precise | released | 1.4.11-3ubuntu2.6 |
saucy | released | 1.4.14-1ubuntu2.2 |
trusty | released | 1.4.16-1ubuntu2.1 |
trusty/esm | not-affected | 1.4.16-1ubuntu2.1 |
upstream | released | 1.4.17,1.4.16-1.2 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 2.0.24-1ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [2.0.22-3ubuntu1.1]] |
lucid | ignored | end of life |
precise | released | 2.0.17-2ubuntu2.12.04.4 |
saucy | released | 2.0.20-1ubuntu3.1 |
trusty | released | 2.0.22-3ubuntu1.1 |
trusty/esm | DNE | trusty was released [2.0.22-3ubuntu1.1] |
upstream | released | 2.0.24 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.1 ...
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
EPSS
5 Medium
CVSS2