GnuPG parse-packet.c 远程缓冲区溢出漏洞

漏洞信息详情

GnuPG parse-packet.c 远程缓冲区溢出漏洞

漏洞简介

GnuPG (gpg) 1.4.3和1.9.20及之前版本中的parse-packet.c远程攻击者借助可能会导致整数溢出的具有大长度(长的用户ID字符串)的消息包,引起拒绝服务(gpg崩溃),比如使用–no-armor选项。

漏洞公告

参考网址

来源: UBUNTU

名称: USN-304-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-304-1

来源: BID

名称: 18554

链接:http://www.securityfocus.com/bid/18554

来源: BUGTRAQ

名称: 20060629 rPSA-2006-0120-1 gnupg

链接:http://www.securityfocus.com/archive/1/archive/1/438751/100/0/threaded

来源: SUSE

名称: SUSE-SR:2006:015

链接:http://www.novell.com/linux/security/advisories/2006_38_security.html

来源: VUPEN

名称: ADV-2006-2450

链接:http://www.frsirt.com/english/advisories/2006/2450

来源: DEBIAN

名称: DSA-1107

链接:http://www.debian.org/security/2006/dsa-1107

来源: SLACKWARE

名称: SSA:2006-178-02

链接:http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.457382

来源: SECUNIA

名称: 20968

链接:http://secunia.com/advisories/20968

来源: SECUNIA

名称: 20899

链接:http://secunia.com/advisories/20899

来源: SECUNIA

名称: 20881

链接:http://secunia.com/advisories/20881

来源: SECUNIA

名称: 20829

链接:http://secunia.com/advisories/20829

来源: SECUNIA

名称: 20811

链接:http://secunia.com/advisories/20811

来源: SECUNIA

名称: 20801

链接:http://secunia.com/advisories/20801

来源: SECUNIA

名称: 20783

链接:http://secunia.com/advisories/20783

来源: FULLDISC

名称: 20060601 Re: GnuPG fun

链接:http://seclists.org/lists/fulldisclosure/2006/May/0789.html

来源: FULLDISC

名称: 20060531 RE: GnuPG fun

链接:http://seclists.org/lists/fulldisclosure/2006/May/0782.html

来源: FULLDISC

名称: 20060531 GnuPG fun

链接:http://seclists.org/lists/fulldisclosure/2006/May/0774.html

来源: MANDRIVA

名称: MDKSA-2006:110

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:110

来源: cvs.gnupg.org

链接:http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/trunk/g10/parse-packet.c?rev=4157&r1=4141&r2=4157

来源: XF

名称: gnupg-parsepacket-bo(27245)

链接:http://xforce.iss.net/xforce/xfdb/27245

来源: REDHAT

名称: RHSA-2006:0571

链接:http://www.redhat.com/support/errata/RHSA-2006-0571.html

来源: OPENPKG

名称: OpenPKG-SA-2006.010

链接:http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.010.html

来源: SUSE

名称: SUSE-SR:2006:018

链接:http://www.novell.com/linux/security/advisories/2006_18_sr.html

来源: MANDRIVA

名称: MDKSA-2006:110

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:110

来源: DEBIAN

名称: DSA-1115

链接:http://www.debian.org/security/2006/dsa-1115

来源: support.avaya.com

链接:http://support.avaya.com/elmodocs2/security/ASA-2006-167.htm

来源: SECTRACK

名称: 1016519

链接:http://securitytracker.com/id?1016519

来源: SECUNIA

名称: 21585

链接:http://secunia.com/advisories/21585

来源: SECUNIA

名称: 21143

链接:http://secunia.com/advisories/21143

来源: SECUNIA

名称: 21137

链接:http://secunia.com/advisories/21137

来源: SECUNIA

名称: 21135

链接:http://secunia.com/advisories/21135

来源: SECUNIA

名称: 21063

链接:http://secunia.com/advisories/21063

来源: SGI

名称: 20060701-01-U

链接:ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享