Total vulnerabilities in the database
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Software | From | Fixed in |
---|---|---|
mageia / mageia | 3.0 | 3.0.x |
mageia / mageia | 4.0 | 4.0.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 7.0 | 7.0.x |
canonical / ubuntu_linux | 14.10 | 14.10.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
gnupg / gnupg | 2.1.0-beta1 | 2.1.0-beta1.x |
gnupg / gnupg | 2.1.0 | 2.1.0.x |
gnupg / libksba | - | 1.3.2 |