CVE-2015-1606

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
20/11/2019
Last modified:
07/11/2023

Description

The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 2.1.2 (excluding)
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*