CVE-2011-2207
published 2019-11-27CVE-2011-2207: dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.20%
64.8th percentile
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| dirmngr | dirmngr | — | — |
| dirmngr | dirmngr | — | — |
| gnupg | gnupg | < 2.1.0 | 2.1.0 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dirmngr: Improper dealing with blocking system calls, when verifying a certificate
vendor_redhat·2011-05-20·CVSS 5.3
CVE-2011-2207 [MEDIUM] dirmngr: Improper dealing with blocking system calls, when verifying a certificate
dirmngr: Improper dealing with blocking system calls, when verifying a certificate
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
Statement: Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.
Package: dirmngr (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-5j88-3pcx-mp3f: dirmngr before 2
ghsa_unreviewed·2022-04-22
CVE-2011-2207 [MEDIUM] CWE-295 GHSA-5j88-3pcx-mp3f: dirmngr before 2
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2011-2207https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627377https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2207https://security-tracker.debian.org/tracker/CVE-2011-2207https://www.openwall.com/lists/oss-security/2011/06/15/6https://access.redhat.com/security/cve/cve-2011-2207https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627377https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-2207https://security-tracker.debian.org/tracker/CVE-2011-2207https://www.openwall.com/lists/oss-security/2011/06/15/6
2019-11-27
Published