CVE Vulnerabilities

CVE-2014-9087

Integer Underflow (Wrap or Wraparound)

Published: Dec 01, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

NameVendorStart VersionEnd Version
MageiaMageia3.0 (including)3.0 (including)
MageiaMageia4.0 (including)4.0 (including)
LibksbaUbuntulucid*
LibksbaUbuntuprecise*
LibksbaUbuntutrusty*
LibksbaUbuntuupstream*
LibksbaUbuntuutopic*

References