parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnupg2 | Jul 30, 2024 | Jun 19, 2006 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 21, 2013 |
| Freebsd | — | Upgrade gnupg | Dec 10, 2025 | Jun 25, 2006 |
| Suse | — | Upgrade gpg | Feb 17, 2015 | Jun 19, 2006 |
| Ubuntu | — | Upgrade gnupg | Nov 8, 2024 | Jun 19, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub