The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnupgUpgrade gnupg2Upgrade gnupg2-smime | Dec 1, 2016 | Jan 23, 2013 |
| Debian | — | Upgrade gnupg2 | Jul 30, 2024 | Jan 24, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 19, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/libgcrypt.Upgrade app-crypt/gnupg. | Oct 30, 2017 | Jan 23, 2013 |
| Oracle_linux | — | Upgrade gnupg2-smimeUpgrade gnupg2 | Oct 16, 2024 | Jan 24, 2013 |
| Suse | — | Upgrade gpg2Upgrade gpg2-lang | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gnupg2Upgrade gnupg | Nov 8, 2024 | Jan 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub