CVE-2015-1607

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/11/2019
Last modified:
07/11/2023

Description

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 1.4.19 (excluding)
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 2.0 (including) 2.0.27 (excluding)
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.2 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*