CVE-2006-6169
published 2006-11-29CVE-2006-6169: Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.17%
86.6th percentile
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnupg2 | < gnupg2 2.0.0-5.1 (bookworm) | gnupg2 2.0.0-5.1 (bookworm) |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xr2-gxmf-xc8r: Heap-based buffer overflow in the ask_outfile_name function in openfile
ghsa_unreviewed·2022-05-03
CVE-2006-6169 [MEDIUM] GHSA-5xr2-gxmf-xc8r: Heap-based buffer overflow in the ask_outfile_name function in openfile
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
OSV
CVE-2006-6169: Heap-based buffer overflow in the ask_outfile_name function in openfile
osv·2006-11-29·CVSS 6.8
CVE-2006-6169 [MEDIUM] CVE-2006-6169: Heap-based buffer overflow in the ask_outfile_name function in openfile
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
Ubuntu
GnuPG2 vulnerabilities
vendor_ubuntu·2006-12-07·CVSS 6.8
CVE-2006-6169 [MEDIUM] GnuPG2 vulnerabilities
Title: GnuPG2 vulnerabilities
Summary: GnuPG2 vulnerabilities
USN-389-1 and USN-393-1 fixed vulnerabilities in gnupg. This update
provides the corresponding updates for gnupg2.
Original advisory details:
A buffer overflow was discovered in GnuPG. By tricking a user into
running gpg interactively on a specially crafted message, an attacker
could execute arbitrary code with the user's privileges. This
vulnerability is not exposed when running gpg in batch mode.
(CVE-2006-6169)
Tavis Ormandy discovered that gnupg was incorrectly using the stack.
If a user were tricked into processing a specially crafted message, an
attacker could execute arbitrary code with the user's privileges.
(CVE-2006-6235)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary ch
Red Hat
: gnupg2 < 2.0.1 buffer overflow
vendor_redhat·2006-11-24·CVSS 6.8
CVE-2006-6169 [MEDIUM] : gnupg2 < 2.0.1 buffer overflow
: gnupg2 < 2.0.1 buffer overflow
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
Statement: Red Hat does not consider this bug to be a security flaw. In order for this flaw to be exploited, a user would be required to enter shellcode into an interactive GnuPG session. Red Hat considers this to be an unlikely scenario.
Red Hat Enterprise Linux 5 contains a backported patch to address this issue.
Debian
CVE-2006-6169: gnupg2 - Heap-based buffer overflow in the ask_outfile_name function in openfile.c for Gn...
vendor_debian·2006·CVSS 6.8
CVE-2006-6169 [MEDIUM] CVE-2006-6169: gnupg2 - Heap-based buffer overflow in the ask_outfile_name function in openfile.c for Gn...
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.
Scope: local
bookworm: resolved (fixed in 2.0.0-5.1)
bullseye: resolved (fixed in 2.0.0-5.1)
forky: resolved (fixed in 2.0.0-5.1)
sid: resolved (fixed in 2.0.0-5.1)
trixie: resolved (fixed in 2.0.0-5.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-6169 GnuPG heap overflow
bugzilla·2006-12-05·CVSS 6.8
CVE-2006-6169 [MEDIUM] CVE-2006-6169 GnuPG heap overflow
CVE-2006-6169 GnuPG heap overflow
Description of problem:
If make_printable_string() returns a string longer than one given as an
argument, a heap-based buffer overflow occurs in openfile.c:ask_outfile_name()
Version-Release number of selected component (if applicable):
RHEL-2.1, RHEL-3, RHEL-4, RHEL-5, FC-5, FC-6
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0754.html
Bugzilla
CVE-2006-6169 GnuPG heap overflow
bugzilla·2006-12-05·CVSS 6.8
CVE-2006-6169 [MEDIUM] CVE-2006-6169 GnuPG heap overflow
CVE-2006-6169 GnuPG heap overflow
+++ This bug was initially created as a clone of Bug #218505 +++
Description of problem:
If make_printable_string() returns a string longer than one given as an
argument, a heap-based buffer overflow occurs in openfile.c:ask_outfile_name()
Version-Release number of selected component (if applicable):
RHEL-2.1, RHEL-3, RHEL-4, RHEL-5, FC-5, FC-6
Discussion:
This was fixed by the update to 1.4.6-2. Closing.
Bugzilla
CVE-2006-6169: gnupg2 < 2.0.1 buffer overflow
bugzilla·2006-11-30·CVSS 6.8
CVE-2006-6169 [MEDIUM] CVE-2006-6169: gnupg2 < 2.0.1 buffer overflow
CVE-2006-6169: gnupg2 2.0.1-1
- gnupg-2.0.1
- CVE-2006-6169 (bug #217950)
FC-3/4/5:
* Fri Dec 01 2006 Rex Dieter 1.9.22-8
- CVE-2006-6169 (bug #217950)
- --disable-optmization on 64bit archs
ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.aschttp://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000241.htmlhttp://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.htmlhttp://secunia.com/advisories/23094http://secunia.com/advisories/23110http://secunia.com/advisories/23146http://secunia.com/advisories/23161http://secunia.com/advisories/23171http://secunia.com/advisories/23250http://secunia.com/advisories/23269http://secunia.com/advisories/23284http://secunia.com/advisories/23299http://secunia.com/advisories/23303http://secunia.com/advisories/23513http://secunia.com/advisories/24047http://security.gentoo.org/glsa/glsa-200612-03.xmlhttp://securityreason.com/securityalert/1927http://securitytracker.com/id?1017291http://support.avaya.com/elmodocs2/security/ASA-2007-047.htmhttp://www.debian.org/security/2006/dsa-1231http://www.mandriva.com/security/advisories?name=MDKSA-2006:221http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0754.htmlhttp://www.securityfocus.com/archive/1/452829/100/0/threadedhttp://www.securityfocus.com/archive/1/453253/100/100/threadedhttp://www.securityfocus.com/bid/21306http://www.trustix.org/errata/2006/0068/http://www.ubuntu.com/usn/usn-389-1http://www.ubuntu.com/usn/usn-393-2http://www.vupen.com/english/advisories/2006/4736https://bugs.g10code.com/gnupg/issue728https://exchange.xforce.ibmcloud.com/vulnerabilities/30550https://issues.rpath.com/browse/RPL-826https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11228ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.aschttp://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000241.htmlhttp://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.htmlhttp://secunia.com/advisories/23094http://secunia.com/advisories/23110http://secunia.com/advisories/23146http://secunia.com/advisories/23161http://secunia.com/advisories/23171http://secunia.com/advisories/23250http://secunia.com/advisories/23269http://secunia.com/advisories/23284http://secunia.com/advisories/23299http://secunia.com/advisories/23303http://secunia.com/advisories/23513http://secunia.com/advisories/24047http://security.gentoo.org/glsa/glsa-200612-03.xmlhttp://securityreason.com/securityalert/1927http://securitytracker.com/id?1017291http://support.avaya.com/elmodocs2/security/ASA-2007-047.htmhttp://www.debian.org/security/2006/dsa-1231http://www.mandriva.com/security/advisories?name=MDKSA-2006:221http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0754.htmlhttp://www.securityfocus.com/archive/1/452829/100/0/threadedhttp://www.securityfocus.com/archive/1/453253/100/100/threadedhttp://www.securityfocus.com/bid/21306http://www.trustix.org/errata/2006/0068/http://www.ubuntu.com/usn/usn-389-1http://www.ubuntu.com/usn/usn-393-2http://www.vupen.com/english/advisories/2006/4736https://bugs.g10code.com/gnupg/issue728https://exchange.xforce.ibmcloud.com/vulnerabilities/30550https://issues.rpath.com/browse/RPL-826https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11228
2006-11-29
Published