cbcvebase.
CVE-2012-6085
published 2013-01-24

CVE-2012-6085: The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the…

PriorityP423medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
2.91%
85.4th percentile
The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiangnupg2< gnupg2 2.0.19-2 (bookworm)gnupg2 2.0.19-2 (bookworm)
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg
gnupggnupg

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.