Lucene search

K
freebsdFreeBSD749B5587-2DA1-11E3-B1A9-B499BAAB0CBE
HistoryOct 05, 2013 - 12:00 a.m.

gnupg -- possible infinite recursion in the compressed packet parser

2013-10-0500:00:00
vuxml.freebsd.org
9

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.045

Percentile

92.5%

Werner Koch reports:

Special crafted input data may be used to cause a denial of service
against GPG (GnuPG’s OpenPGP part) and some other OpenPGP
implementations. All systems using GPG to process incoming data are
affected…

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgnupg< 1.4.15UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.045

Percentile

92.5%