In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NGnupg
APPGnupg≤ 2.4.8
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Memory
Referencje
Powiązane podatności
CVE-2022-3515CRITICAL9.8PL ✓ten sam produkt
Integer overflow w bibliotece Libksba umożliwiający zdalne wykonanie kodu
CVE-2026-24882HIGH8.4ten sam produkt
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT co...
CVE-2026-24881HIGH8.1ten sam produkt
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key...
CVE-2020-25125HIGH7.8ten sam produkt
GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified...
CVE-2019-14855HIGH7.5ten sam produkt
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorit...