cbcvebase.

Debian Gnupg2 vulnerabilities

24 known vulnerabilities affecting debian/gnupg2.

Total CVEs
24
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM11LOW7

Vulnerabilities

Page 2 of 2
CVE-2014-4617P4MEDIUMCVSS 5.0fixed in gnupg2 2.0.24-1 (bookworm)2014
CVE-2014-4617 [MEDIUM] CVE-2014-4617: gnupg2 - The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x ... The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence. Scope: local bookworm: resolved (fixed in 2.0.24-1) bullseye: resolved (fixed in 2.0.24-1) forky: resolved (fixe
debian
CVE-2015-1607P4MEDIUMCVSS 5.5fixed in gnupg2 2.0.26-5 (bookworm)2015
CVE-2015-1607 [MEDIUM] CVE-2015-1607: gnupg2 - kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x befor... kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges." Scope: local bookworm: resolved (fixed in 2.0.26-5) bullse
debian
CVE-2015-1606P4MEDIUMCVSS 5.5fixed in gnupg2 2.0.26-5 (bookworm)2015
CVE-2015-1606 [MEDIUM] CVE-2015-1606: gnupg2 - The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, w... The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file. Scope: local bookworm: resolved (fixed in 2.0.26-5) bullseye: resolved (fixed in 2.0.26-5) forky: resolved (fixed in 2.0.26-5) sid: resolved (fixed in 2.0.26-5) trixie:
debian
CVE-2025-30258P4LOWCVSS 2.7fixed in gnupg2 2.2.46-5 (forky)2025
CVE-2025-30258 [LOW] CVE-2025-30258: gnupg2 - In GnuPG before 2.5.5, if a user chooses to import a certificate with certain cr... In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS." Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.2.46-5) sid: resolved (fixe
debian
Debian Gnupg2 vulnerabilities | cvebase