CVE-2008-1530
published 2008-03-27CVE-2008-1530: GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.04%
89.4th percentile
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnupg2 | < gnupg2 2.0.9-1 (bookworm) | gnupg2 2.0.9-1 (bookworm) |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9r93-hrx4-h834: GnuPG (gpg) 1
ghsa_unreviewed·2022-05-01
CVE-2008-1530 [HIGH] GHSA-9r93-hrx4-h834: GnuPG (gpg) 1
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
OSV
CVE-2008-1530: GnuPG (gpg) 1
osv·2008-03-27·CVSS 9.3
CVE-2008-1530 [CRITICAL] CVE-2008-1530: GnuPG (gpg) 1
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
Debian
CVE-2008-1530: gnupg2 - GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service...
vendor_debian·2008·CVSS 9.3
CVE-2008-1530 [CRITICAL] CVE-2008-1530: gnupg2 - GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service...
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
Scope: local
bookworm: resolved (fixed in 2.0.9-1)
bullseye: resolved (fixed in 2.0.9-1)
forky: resolved (fixed in 2.0.9-1)
sid: resolved (fixed in 2.0.9-1)
trixie: resolved (fixed in 2.0.9-1)
Red Hat
gnupg NULL pointer dereference
vendor_redhat·CVSS 9.3
CVE-2008-1530 [CRITICAL] gnupg NULL pointer dereference
gnupg NULL pointer dereference
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
Statement: Not vulnerable. This issue does not affect the versions of gnupg packages as shipped with Red Hat Enterprise Linux versions 2.1, 3, 4 or 5.
No detection rules found.
No public exploits indexed.
http://lists.gnupg.org/pipermail/gnupg-announce/2008q1/000272.htmlhttp://secunia.com/advisories/29568http://www.ocert.org/advisories/ocert-2008-1.htmlhttp://www.securityfocus.com/bid/28487http://www.vupen.com/english/advisories/2008/1056/referenceshttps://bugs.g10code.com/gnupg/issue894https://bugs.gentoo.org/show_bug.cgi?id=214990https://exchange.xforce.ibmcloud.com/vulnerabilities/41547http://lists.gnupg.org/pipermail/gnupg-announce/2008q1/000272.htmlhttp://secunia.com/advisories/29568http://www.ocert.org/advisories/ocert-2008-1.htmlhttp://www.securityfocus.com/bid/28487http://www.vupen.com/english/advisories/2008/1056/referenceshttps://bugs.g10code.com/gnupg/issue894https://bugs.gentoo.org/show_bug.cgi?id=214990https://exchange.xforce.ibmcloud.com/vulnerabilities/41547
2008-03-27
Published