Back

MEDIUM

: gnupg2 < 2.0.1 buffer overflow

Published Nov 29, 2006

Description

Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.

Affected products

Remediation

Red Hat statement

Red Hat does not consider this bug to be a security flaw. In order for this flaw to be exploited, a user would be required to enter shellcode into an interactive GnuPG session. Red Hat considers this to be an unlikely scenario. Red Hat Enterprise Linux 5 contains a backported patch to address this issue.

Weaknesses (0)

No CWE recorded.

References (39)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 29, 2006
Updated Aug 7, 2024
Reserved Nov 29, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 24, 2006
ENISA EUVD
Assigner mitre
Published Nov 29, 2006
Updated Aug 7, 2024
Exploited since n/a
EUVD-2006-6152