CVE-2014-4617
Public on 2014-06-25
Modified on 2019-05-03
Description
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | gnupg | 2014-07-23 | ALAS-2014-378 | Fixed |
Amazon Linux 1 | gnupg2 | 2014-07-23 | ALAS-2014-379 | Fixed |
Amazon Linux 2 - Core | gnupg2 | 2019-05-02 | ALAS2-2019-1203 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:N/I:N/A:P |