Stack Overwrite Vulnerability in GnuPG Affects Versions Below 1.4.6 and 2.0.2
CVE-2006-6235
Currently unrated
What is CVE-2006-6235?
GnuPG versions prior to 1.4.6 and 2.0.2 are affected by a stack overwrite vulnerability, enabling attackers to execute arbitrary code. This issue arises when crafted OpenPGP packets are processed, causing GnuPG to dereference a function pointer from deallocated stack memory. This vulnerability poses a significant risk as it may allow unauthorized execution of commands on affected systems.