The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the xa3x03 string.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora | Fedoraproject | 22 (including) | 22 (including) |
Fedora | Fedoraproject | 23 (including) | 23 (including) |
Fedora | Fedoraproject | 24 (including) | 24 (including) |
Pgpdump | Ubuntu | esm-apps/xenial | * |
Pgpdump | Ubuntu | precise | * |
Pgpdump | Ubuntu | trusty | * |
Pgpdump | Ubuntu | upstream | * |
Pgpdump | Ubuntu | wily | * |
Pgpdump | Ubuntu | xenial | * |
Pgpdump | Ubuntu | yakkety | * |