GnuPG Parse_Comment Remote Buffer Overflow
Published Jul 28, 2006
5.0
MEDIUMCVSS 2.0
EPSS 7.21%
Description
Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
gnupg-0:1.2.1-17
Fixed · RHSA-2006:0615
Red Hat Enterprise Linux 4
gnupg-0:1.2.6-6
Fixed · RHSA-2006:0615
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | gnupg-0:1.2.1-17 | Fixed | RHSA-2006:0615 |
| Red Hat Enterprise Linux 4 | gnupg-0:1.2.6-6 | Fixed | RHSA-2006:0615 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 7.21% (0.07214) | 94.14th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.67% (0.06671) | 93.01th | v5 (v2026.06.15) |
| Feb 27, 2026 | 35.26% (0.35261) | 96.95th | v4 (v2025.03.14) |
| Mar 30, 2025 | 32.69% (0.32693) | 96.49th | v4 (v2025.03.14) |
| Mar 29, 2025 | 29.90% (0.29900) | 94.70th | v4 (v2025.03.14) |
| Mar 17, 2025 | 32.69% (0.32693) | 96.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 77.97% (0.77973) | 98.35th | v3 (v2023.03.01) |
| Nov 16, 2024 | 77.97% (0.77973) | 98.33th | v3 (v2023.03.01) |
| Jun 17, 2024 | 81.40% (0.81396) | 98.38th | v3 (v2023.03.01) |
| Apr 2, 2024 | 89.60% (0.89600) | 98.71th | v3 (v2023.03.01) |
| Feb 7, 2024 | 87.96% (0.87958) | 98.42th | v3 (v2023.03.01) |
| Dec 21, 2023 | 87.61% (0.87611) | 98.37th | v3 (v2023.03.01) |
| Jun 1, 2023 | 89.73% (0.89731) | 98.25th | v3 (v2023.03.01) |
| Apr 24, 2023 | 93.22% (0.93217) | 98.54th | v3 (v2023.03.01) |
| Mar 17, 2023 | 93.32% (0.93316) | 98.50th | v3 (v2023.03.01) |
| Mar 7, 2023 | 93.38% (0.93380) | 98.49th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
No CWE recorded.
References (40)
- ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P vendor-advisoryx_refsource_SGI
- http://bugs.debian.org/cgi-bin/bugreport.cgi/gnupg.CVE-2006-3746.diff?bug=381204%3Bmsg=15%3Batt=1 x_refsource_MISC
- http://issues.rpath.com/browse/RPL-560 x_refsource_MISC
- http://lists.immunitysec.com/pipermail/dailydave/2006-July/003354.html mailing-listx_refsource_MLISTExploit
- http://lwn.net/Alerts/194228/ vendor-advisoryx_refsource_TRUSTIX
- http://secunia.com/advisories/21297 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21300 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21306 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21326 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21329 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21333 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21346 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21351 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21378 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21467 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21522 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21524 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/21598 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200608-08.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1016622 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2006-164.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1140 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2006/dsa-1141 vendor-advisoryx_refsource_DEBIAN
- http://www.gossamer-threads.com/lists/gnupg/devel/37623 mailing-listx_refsource_MLIST
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:141 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_20_sr.html vendor-advisoryx_refsource_SUSE
- http://www.osvdb.org/27664 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0615.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/442012/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/442621/100/100/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19110 vdb-entryx_refsource_BIDExploit
- http://www.ubuntu.com/usn/usn-332-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/3123 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-3746 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=200502 x_refsource_MISCExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=200502 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28220 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-3746
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11347 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-3746
Change history (0)
No recorded changes yet.