gnupg2

Page content
  • Author: voroskoi
  • Vulnerable: 2.0.8-1
  • Unaffected: 2.0.9-1kalgan1

A vulnerability has been reported in GnuPG, which can potentially be exploited to compromise a vulnerable system. The vulnerability is caused due to an error when importing keys with duplicated IDs. This can be exploited to cause a memory corruption when importing keys via –refresh-keys or –import. Successful exploitation potentially allows execution of arbitrary code, but has not been proven yet.

CVEs: