CVE Vulnerabilities

CVE-2016-4021

Published: May 26, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the xa3x03 string.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject22 (including)22 (including)
FedoraFedoraproject23 (including)23 (including)
FedoraFedoraproject24 (including)24 (including)
PgpdumpUbuntuesm-apps/xenial*
PgpdumpUbuntuesm-infra-legacy/trusty*
PgpdumpUbuntuprecise*
PgpdumpUbuntutrusty*
PgpdumpUbuntutrusty/esm*
PgpdumpUbuntuupstream*
PgpdumpUbuntuwily*
PgpdumpUbuntuxenial*
PgpdumpUbuntuyakkety*

References