Back to search
CVE-2014-4617
Published: Jun 25, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
59351
third-party-advisory
x_refsource_SECUNIA
59578
third-party-advisory
x_refsource_SECUNIA
[gnupg-announce] 20140624 [security fix] GnuPG 2.0.24 released
mailing-list
x_refsource_MLIST
DSA-2967
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2014:0866
vendor-advisory
x_refsource_SUSE
USN-2258-1
vendor-advisory
x_refsource_UBUNTU
DSA-2968
vendor-advisory
x_refsource_DEBIAN
59534
third-party-advisory
x_refsource_SECUNIA
59213
third-party-advisory
x_refsource_SECUNIA
[gnupg-announce] 20140623 [security fix] GnuPG 1.4.17 released
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now