Skip to main content

GnuPG do_uncompress() Compressed Data Processing Flaw

Last Update Date: 27 Jun 2014 Release Date: 26 Jun 2014 2979 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in GnuPG. A remote user can cause denial of service conditions.

 

A remote user can send specially crafted compressed data packets to trigger a flaw in do_uncompress() and cause the target process to enter an infinite loop.


Impact

  • Denial of Service

System / Technologies affected

  • Prior to versions 1.4.17, 2.0.24

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (3.6.24, 4.0.19, 4.1.9).

Vulnerability Identifier


Source


Related Link