Input validation error in GnuPG - CVE-2014-4617

 

Input validation error in GnuPG - CVE-2014-4617

Published: June 25, 2014 / Updated: July 28, 2020


Vulnerability identifier: #VU32509
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-4617
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.


Affected software

GnuPG
Gentoo Linux
Amazon Linux AMI
Slackware Linux
gnupg1 (Alpine package)
gnupg (Alpine package)

How to mitigate CVE-2014-4617

Install update from vendor's website.

GnuPG - update to 1.4.17
gnupg1 (Alpine package) - update to 1.4.17-r0
gnupg (Alpine package) - update to 2.0.24-r0

External References

Related Security Bulletins