CVE-2014-9087
published 2014-12-01CVE-2014-9087: Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.17%
91.5th percentile
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | gnupg2 | < libksba 1.3.2-1 (bookworm) | libksba 1.3.2-1 (bookworm) |
| debian | libksba | < libksba 1.3.2-1 (bookworm) | libksba 1.3.2-1 (bookworm) |
| gnupg | gnupg | — | — |
| gnupg | libksba | < 1.3.2 | 1.3.2 |
| gnupg | libksba | >= 0 < 1.3.2-1 | 1.3.2-1 |
| gnupg | libksba | >= 0 < 1.3.2-1 | 1.3.2-1 |
| gnupg | libksba | >= 0 < 1.3.2-1 | 1.3.2-1 |
| gnupg | libksba | >= 0 < 1.3.2-1 | 1.3.2-1 |
| mageia | mageia | — | — |
| mageia | mageia | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqgr-f24j-7rxx: Integer underflow in the ksba_oid_to_str function in Libksba before 1
ghsa_unreviewed·2022-05-13
CVE-2014-9087 [HIGH] CWE-191 GHSA-vqgr-f24j-7rxx: Integer underflow in the ksba_oid_to_str function in Libksba before 1
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
OSV
CVE-2014-9087: Integer underflow in the ksba_oid_to_str function in Libksba before 1
osv·2014-12-01·CVSS 7.5
CVE-2014-9087 [HIGH] CVE-2014-9087: Integer underflow in the ksba_oid_to_str function in Libksba before 1
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Ubuntu
Libksba vulnerability
vendor_ubuntu·2014-11-27
CVE-2014-9087 Libksba vulnerability
Title: Libksba vulnerability
Summary: Libksba could be made to crash or run programs if it opened a specially
crafted file.
Hanno Böck discovered that Libksba incorrectly handled certain S/MIME
messages or ECC based OpenPGP data. An attacker could use this issue to
cause Libksba to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libksba: integer underflow flaw leading to a heap-based buffer overflow in ksba_oid_to_str()
vendor_redhat·2014-11-25·CVSS 7.5
CVE-2014-9087 [HIGH] CWE-190 libksba: integer underflow flaw leading to a heap-based buffer overflow in ksba_oid_to_str()
libksba: integer underflow flaw leading to a heap-based buffer overflow in ksba_oid_to_str()
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Package: libksba (Red Hat Enterprise Linux 5) - Will not fix
Package: libksba (Red Hat Enterprise Linux 6) - Will not fix
Package: libksba (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9087: gnupg2 - Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as us...
vendor_debian·2014·CVSS 7.5
CVE-2014-9087 [HIGH] CVE-2014-9087: gnupg2 - Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as us...
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0498.htmlhttp://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlhttp://secunia.com/advisories/60073http://secunia.com/advisories/60189http://secunia.com/advisories/60233http://www.debian.org/security/2014/dsa-3078http://www.mandriva.com/security/advisories?name=MDVSA-2014:234http://www.mandriva.com/security/advisories?name=MDVSA-2015:151http://www.securityfocus.com/bid/71285http://www.ubuntu.com/usn/USN-2427-1https://blog.fuzzing-project.org/2-Buffer-overflow-and-other-minor-issues-in-GnuPG-and-libksba-TFPA-0012014.htmlhttp://advisories.mageia.org/MGASA-2014-0498.htmlhttp://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlhttp://secunia.com/advisories/60073http://secunia.com/advisories/60189http://secunia.com/advisories/60233http://www.debian.org/security/2014/dsa-3078http://www.mandriva.com/security/advisories?name=MDVSA-2014:234http://www.mandriva.com/security/advisories?name=MDVSA-2015:151http://www.securityfocus.com/bid/71285http://www.ubuntu.com/usn/USN-2427-1https://blog.fuzzing-project.org/2-Buffer-overflow-and-other-minor-issues-in-GnuPG-and-libksba-TFPA-0012014.html
2014-12-01
Published