The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnupg2Upgrade gnupg2-smimeUpgrade gnupg | Dec 1, 2016 | Oct 28, 2013 |
| Debian | — | Upgrade gnupg2Upgrade gnupg | Jul 30, 2024 | Oct 28, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 19, 2016 |
| Freebsd | — | Upgrade gnupg | Dec 10, 2025 | Oct 5, 2013 |
| Gentoo Linux | — | Upgrade app-crypt/gnupg.Upgrade dev-libs/libgcrypt. | Oct 30, 2017 | Oct 28, 2013 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Oct 28, 2013 |
| Oracle_linux | — | Upgrade gnupg2Upgrade gnupg2-smime | Oct 16, 2024 | Oct 28, 2013 |
| Suse | — | Upgrade gpg2-langUpgrade gpgUpgrade gpg2 | Dec 12, 2013 | Oct 28, 2013 |
| Ubuntu | — | Upgrade gnupgUpgrade gnupg2 | Nov 8, 2024 | Oct 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub