[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2601-1 gnupg, gnupg2 -- missing input sanitation

ID: oval:org.secpod.oval:def:600945Date: (C)2013-01-16   (M)2023-12-07
Class: PATCHFamily: unix




KB Sriram discovered that GnuPG, the GNU Privacy Guard did not sufficiently sanitise public keys on import, which could lead to memory and keyring corruption. The problem affects both version 1, in the "gnupg" package, and version two, in the "gnupg2" package.

Platform:
Debian 6.0
Product:
gnupg
gnupg2
Reference:
DSA-2601-1
CVE-2012-6085
CVE    1
CVE-2012-6085
CPE    30
cpe:/a:gnupg:gnupg:2.0
cpe:/a:gnupg:gnupg:1.4.8
cpe:/o:debian:debian_linux:6.0
cpe:/a:gnupg:gnupg:1.4.12
...

© SecPod Technologies