CVE Vulnerabilities

CVE-2014-9087

Integer Underflow (Wrap or Wraparound)

Published: Dec 01, 2014 | Modified: May 18, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Mageia Mageia 3.0 (including) 3.0 (including)
Mageia Mageia 4.0 (including) 4.0 (including)
Libksba Ubuntu lucid *
Libksba Ubuntu precise *
Libksba Ubuntu trusty *
Libksba Ubuntu upstream *
Libksba Ubuntu utopic *

References