Lucene search

K
ubuntuUbuntuUSN-970-1
HistoryAug 11, 2010 - 12:00 a.m.

GnuPG2 vulnerability

2010-08-1100:00:00
ubuntu.com
42

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.127

Percentile

95.5%

Releases

  • Ubuntu 10.04
  • Ubuntu 9.10
  • Ubuntu 9.04
  • Ubuntu 8.04

Packages

  • gnupg2 -

Details

It was discovered that GPGSM in GnuPG2 did not correctly handle
certificates with a large number of Subject Alternate Names. If a user or
automated system were tricked into processing a specially crafted
certificate, an attacker could cause a denial of service or execute
arbitrary code with privileges of the user invoking the program.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchgpgsm< 2.0.12-0ubuntu2.1UNKNOWN
Ubuntu9.10noarchgnupg-agent< 2.0.12-0ubuntu2.1UNKNOWN
Ubuntu9.10noarchgnupg2< 2.0.12-0ubuntu2.1UNKNOWN
Ubuntu9.04noarchgpgsm< 2.0.9-3.1ubuntu0.1UNKNOWN
Ubuntu9.04noarchgnupg-agent< 2.0.9-3.1ubuntu0.1UNKNOWN
Ubuntu9.04noarchgnupg2< 2.0.9-3.1ubuntu0.1UNKNOWN
Ubuntu8.04noarchgpgsm< 2.0.7-1ubuntu0.1UNKNOWN
Ubuntu8.04noarchgnupg-agent< 2.0.7-1ubuntu0.1UNKNOWN
Ubuntu8.04noarchgnupg2< 2.0.7-1ubuntu0.1UNKNOWN
Ubuntu10.04noarchgpgsm< 2.0.14-1ubuntu1.2UNKNOWN
Rows per page:
1-10 of 121

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.127

Percentile

95.5%