In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).
| Software | From | Fixed in |
|---|---|---|
| gnupg / gnupg | 2.5.13 | 2.5.17 |
| gpg4win / gpg4win | 5.0.0 | 5.0.1 |