CVE-2006-3082

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
19/06/2006
Last modified:
03/04/2025

Description

parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 1.9.20 (including)
cpe:2.3:a:gnupg:gnupg:1.4.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools