CVE-2014-4617
published 2014-06-25CVE-2014-4617: The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.31%
87.2th percentile
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gnupg2 | < gnupg2 2.0.24-1 (bookworm) | gnupg2 2.0.24-1 (bookworm) |
| gnupg | gnupg | <= 1.4.16 | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
| gnupg | gnupg | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x662-2943-q7qh: The do_uncompress function in g10/compress
ghsa_unreviewed·2022-05-14
CVE-2014-4617 [MEDIUM] CWE-20 GHSA-x662-2943-q7qh: The do_uncompress function in g10/compress
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
OSV
CVE-2014-4617: The do_uncompress function in g10/compress
osv·2014-06-25·CVSS 5.0
CVE-2014-4617 [MEDIUM] CVE-2014-4617: The do_uncompress function in g10/compress
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Ubuntu
GnuPG vulnerability
vendor_ubuntu·2014-06-26
CVE-2014-4617 GnuPG vulnerability
Title: GnuPG vulnerability
Summary: GnuPG could be made to hang if it processed a specially crafted message.
Jean-René Reinhard, Olivier Levillain and Florian Maury discovered that
GnuPG incorrectly handled certain OpenPGP messages. If a user or automated
system were tricked into processing a specially-crafted message, GnuPG
could consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gnupg: infinite loop when decompressing data packets
vendor_redhat·2014-06-20·CVSS 5.0
CVE-2014-4617 [MEDIUM] CWE-835 gnupg: infinite loop when decompressing data packets
gnupg: infinite loop when decompressing data packets
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Package: gnupg (Red Hat Enterprise Linux 5) - Will not fix
Package: gnupg2 (Red Hat Enterprise Linux 5) - Will not fix
Package: gnupg2 (Red Hat Enterprise Linux 6) - Will not fix
Package: gnupg2 (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-4617: gnupg2 - The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x ...
vendor_debian·2014·CVSS 5.0
CVE-2014-4617 [MEDIUM] CVE-2014-4617: gnupg2 - The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x ...
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Scope: local
bookworm: resolved (fixed in 2.0.24-1)
bullseye: resolved (fixed in 2.0.24-1)
forky: resolved (fixed in 2.0.24-1)
sid: resolved (fixed in 2.0.24-1)
trixie: resolved (fixed in 2.0.24-1)
No detection rules found.
No public exploits indexed.
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git%3Ba=commit%3Bh=014b2103fcb12f261135e3954f26e9e07b39e342http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git%3Ba=commit%3Bh=11fdfcf82bd8d2b5bc38292a29876e10770f4b0ahttp://lists.gnupg.org/pipermail/gnupg-announce/2014q2/000344.htmlhttp://lists.gnupg.org/pipermail/gnupg-announce/2014q2/000345.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00010.htmlhttp://secunia.com/advisories/59213http://secunia.com/advisories/59351http://secunia.com/advisories/59534http://secunia.com/advisories/59578http://www.debian.org/security/2014/dsa-2967http://www.debian.org/security/2014/dsa-2968http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.ubuntu.com/usn/USN-2258-1http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git%3Ba=commit%3Bh=014b2103fcb12f261135e3954f26e9e07b39e342http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git%3Ba=commit%3Bh=11fdfcf82bd8d2b5bc38292a29876e10770f4b0ahttp://lists.gnupg.org/pipermail/gnupg-announce/2014q2/000344.htmlhttp://lists.gnupg.org/pipermail/gnupg-announce/2014q2/000345.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00010.htmlhttp://secunia.com/advisories/59213http://secunia.com/advisories/59351http://secunia.com/advisories/59534http://secunia.com/advisories/59578http://www.debian.org/security/2014/dsa-2967http://www.debian.org/security/2014/dsa-2968http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.ubuntu.com/usn/USN-2258-1
2014-06-25
Published