Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnupg2 | Dec 1, 2016 | Aug 5, 2010 |
| Debian | — | Upgrade gnupg2 | Jul 30, 2024 | Aug 5, 2010 |
| Gentoo Linux | — | Upgrade app-crypt/gnupg. | Oct 30, 2017 | Aug 5, 2010 |
| Oracle_linux | — | Upgrade gnupg2 | Oct 16, 2024 | Aug 5, 2010 |
| Suse | — | Upgrade gpg2-langUpgrade libgcrypt11-32bitUpgrade gpg2Upgrade libgpg-error0Upgrade libgpg-error0-x86Upgrade libgpg-error0-32bitUpgrade libgcrypt11-x86Upgrade libgcrypt11Upgrade dirmngrUpgrade gpg2-tpmUpgrade libksba | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gpgsm | Nov 8, 2024 | Aug 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub