GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers memory corruption around deduplication of user IDs.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gnupg | Gnupg | 1.4.8 (including) | 1.4.8 (including) |
Gnupg | Gnupg | 2.0.8 (including) | 2.0.8 (including) |