CVE Database
/

CVE-2014-9087

Back to search

CVE-2014-9087

Published: Dec 1, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2015:151
vendor-advisory
x_refsource_MANDRIVA
60233
third-party-advisory
x_refsource_SECUNIA
DSA-3078
vendor-advisory
x_refsource_DEBIAN
MDVSA-2014:234
vendor-advisory
x_refsource_MANDRIVA
71285
vdb-entry
x_refsource_BID
60073
third-party-advisory
x_refsource_SECUNIA
60189
third-party-advisory
x_refsource_SECUNIA
USN-2427-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now