CVE Vulnerabilities

CVE-2016-4021

Published: May 26, 2016 | Modified: Jun 15, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the xa3x03 string.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 22 (including) 22 (including)
Fedora Fedoraproject 23 (including) 23 (including)
Fedora Fedoraproject 24 (including) 24 (including)
Pgpdump Ubuntu esm-apps/xenial *
Pgpdump Ubuntu precise *
Pgpdump Ubuntu trusty *
Pgpdump Ubuntu upstream *
Pgpdump Ubuntu wily *
Pgpdump Ubuntu xenial *
Pgpdump Ubuntu yakkety *

References