GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers memory corruption around deduplication of user IDs.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gnupg | Gnupg | 1.4.8 (including) | 1.4.8 (including) |
| Gnupg | Gnupg | 2.0.8 (including) | 2.0.8 (including) |