[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-2547Date: (C)2010-08-05   (M)2024-02-09


Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.1CVSS Score : 5.1
Exploit Score: 2.2Exploit Score: 4.9
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: HIGH
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
SECTRACK-1024247
SECUNIA-38877
SECUNIA-40718
SECUNIA-40841
BID-41945
ADV-2010-1931
ADV-2010-1950
ADV-2010-1988
ADV-2010-2217
ADV-2010-3125
DSA-2076
FEDORA-2010-11413
MDVSA-2010:143
SSA:2010-240-01
SUSE-SR:2010:020
http://lists.gnupg.org/pipermail/gnupg-announce/2010q3/000302.html
http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0076
https://issues.rpath.com/browse/RPL-3229

CWE    1
CWE-416
OVAL    8
oval:org.secpod.oval:def:600091
oval:org.secpod.oval:def:1500282
oval:org.secpod.oval:def:300036
oval:org.secpod.oval:def:201818
...

© SecPod Technologies