Stack Overwrite Vulnerability in GnuPG Affects Versions Below 1.4.6 and 2.0.2
CVE-2006-6235

Currently unrated

Key Information:

Vendor
Gnu
Vendor
CVE Published:
7 December 2006

Summary

GnuPG versions prior to 1.4.6 and 2.0.2 are affected by a stack overwrite vulnerability, enabling attackers to execute arbitrary code. This issue arises when crafted OpenPGP packets are processed, causing GnuPG to dereference a function pointer from deallocated stack memory. This vulnerability poses a significant risk as it may allow unauthorized execution of commands on affected systems.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.