HIGH
security flaw
Published Dec 7, 2006
10.0
HIGHCVSS 2.0
EPSS 5.86%
Description
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
Affected products
No data.
Configuration 1
OR
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.3.3
- 1.3.4
- 1.4
- 1.4.1
- 1.4.2
- 1.4.2.1
- 1.4.2.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.9.10
- 1.9.15
- 1.9.20
- 2.0
- 2.0.1
- 1.0.7
Configuration 2
OR
- 4.0
- 4.0
- 4.0
- 3.0
- 4.0
- core_5.0
- core6
- 2.1
- 1
- 11.0
- 5.10
- 6.06
No data.
Red Hat Enterprise Linux 2.1
gnupg-0:1.0.7-20
Fixed · RHSA-2006:0754
Red Hat Enterprise Linux 3
gnupg-0:1.2.1-19
Fixed · RHSA-2006:0754
Red Hat Enterprise Linux 4
gnupg-0:1.2.6-8
Fixed · RHSA-2006:0754
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | gnupg-0:1.0.7-20 | Fixed | RHSA-2006:0754 |
| Red Hat Enterprise Linux 3 | gnupg-0:1.2.1-19 | Fixed | RHSA-2006:0754 |
| Red Hat Enterprise Linux 4 | gnupg-0:1.2.6-8 | Fixed | RHSA-2006:0754 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Weaknesses (0)
No CWE recorded.
References (39)
- ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.asc vendor-advisoryx_refsource_SGI
- http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000491.html mailing-listx_refsource_MLIST
- http://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/23245 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/23250 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/23255 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/23259 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23269 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/23284 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23290 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23299 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23303 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23329 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23335 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23513 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24047 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200612-03.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1017349 vdb-entryx_refsource_SECTRACK
- http://support.avaya.com/elmodocs2/security/ASA-2007-047.htm x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1231 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/427009 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:228 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_28_sr.html vendor-advisoryx_refsource_SUSE
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.html vendor-advisoryx_refsource_OPENPKG
- http://www.redhat.com/support/errata/RHSA-2006-0754.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/453664/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/453723/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/21462 vdb-entryx_refsource_BIDVendor Advisory
- http://www.trustix.org/errata/2006/0070 vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-393-1 vendor-advisoryx_refsource_UBUNTUPatch
- http://www.ubuntu.com/usn/usn-393-2 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/4881 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-6235 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618242 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30711 vdb-entryx_refsource_XF
- https://issues.rpath.com/browse/RPL-835 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-6235
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11245 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-6235
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 7, 2006
Updated Aug 7, 2024
Reserved Dec 2, 2006
Link CVE-2006-6235
CISA Vulnrichment
Updated n/a