Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnupg2 | Jul 30, 2024 | Nov 29, 2006 |
| Gentoo Linux | — | Upgrade app-crypt/gnupg. | Oct 30, 2017 | Nov 29, 2006 |
| Suse | — | Upgrade gpg2-langUpgrade gpg2-tpmUpgrade dirmngrUpgrade gpg2 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gnupg2 | Nov 8, 2024 | Nov 29, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub