CVE Vulnerabilities

CVE-2006-6235

Published: Dec 07, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A stack overwrite vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

Affected Software

Name Vendor Start Version End Version
Privacy_guard Gnu 1.2.4 (including) 1.2.4 (including)
Privacy_guard Gnu 1.2.5 (including) 1.2.5 (including)
Privacy_guard Gnu 1.2.6 (including) 1.2.6 (including)
Privacy_guard Gnu 1.2.7 (including) 1.2.7 (including)
Privacy_guard Gnu 1.3.3 (including) 1.3.3 (including)
Privacy_guard Gnu 1.3.4 (including) 1.3.4 (including)
Privacy_guard Gnu 1.4 (including) 1.4 (including)
Privacy_guard Gnu 1.4.1 (including) 1.4.1 (including)
Privacy_guard Gnu 1.4.2 (including) 1.4.2 (including)
Privacy_guard Gnu 1.4.2.1 (including) 1.4.2.1 (including)
Privacy_guard Gnu 1.4.2.2 (including) 1.4.2.2 (including)
Privacy_guard Gnu 1.4.3 (including) 1.4.3 (including)
Privacy_guard Gnu 1.4.4 (including) 1.4.4 (including)
Privacy_guard Gnu 1.4.5 (including) 1.4.5 (including)
Privacy_guard Gnu 1.9.10 (including) 1.9.10 (including)
Privacy_guard Gnu 1.9.15 (including) 1.9.15 (including)
Privacy_guard Gnu 1.9.20 (including) 1.9.20 (including)
Privacy_guard Gnu 2.0 (including) 2.0 (including)
Privacy_guard Gnu 2.0.1 (including) 2.0.1 (including)
Gpg4win Gpg4win 1.0.7 (including) 1.0.7 (including)

References