CVE-2006-6235

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
References
Link Resource
http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000491.html
http://www.redhat.com/support/errata/RHSA-2006-0754.html Vendor Advisory
http://www.securityfocus.com/bid/21462 Vendor Advisory
http://secunia.com/advisories/23245 Patch Vendor Advisory
http://www.ubuntu.com/usn/usn-393-1 Patch
http://secunia.com/advisories/23250 Patch Vendor Advisory
http://secunia.com/advisories/23255 Patch Vendor Advisory
http://secunia.com/advisories/23269 Patch Vendor Advisory
https://issues.rpath.com/browse/RPL-835
http://www.debian.org/security/2006/dsa-1231
http://security.gentoo.org/glsa/glsa-200612-03.xml
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.html
http://www.trustix.org/errata/2006/0070
http://www.ubuntu.com/usn/usn-393-2
http://securitytracker.com/id?1017349
http://secunia.com/advisories/23259
http://secunia.com/advisories/23299
http://secunia.com/advisories/23303
http://secunia.com/advisories/23329
http://www.mandriva.com/security/advisories?name=MDKSA-2006:228
http://www.novell.com/linux/security/advisories/2006_28_sr.html
http://secunia.com/advisories/23290
http://secunia.com/advisories/23335
http://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.html
http://www.kb.cert.org/vuls/id/427009 US Government Resource
http://secunia.com/advisories/23284
ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.asc
http://secunia.com/advisories/23513
http://support.avaya.com/elmodocs2/security/ASA-2007-047.htm
http://secunia.com/advisories/24047
http://www.vupen.com/english/advisories/2006/4881
https://exchange.xforce.ibmcloud.com/vulnerabilities/30711
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11245
http://www.securityfocus.com/archive/1/453723/100/0/threaded
http://www.securityfocus.com/archive/1/453664/100/0/threaded
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:privacy_guard:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.9.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.9.15:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gpg4win:gpg4win:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.9.20:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:2.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.4.2.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:4.0:*:enterprise_server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*:workstation:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:5.10:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*:advanced_server:*:*:*:*:*
cpe:2.3:o:redhat:linux_advanced_workstation:2.1:*:itanium_processor:*:*:*:*:*
cpe:2.3:o:rpath:linux:1:*:*:*:*:*:*:*
cpe:2.3:o:slackware:slackware_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:3.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:fedora_core:core_5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:fedora_core:core6:*:*:*:*:*:*:*

Information

Published : 2006-12-07 03:28

Updated : 2018-10-17 14:47


NVD link : CVE-2006-6235

Mitre link : CVE-2006-6235


JSON object : View

Advertisement

dedicated server usa

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux
  • fedora_core
  • linux_advanced_workstation

slackware

  • slackware_linux

gnu

  • privacy_guard

ubuntu

  • ubuntu_linux

gpg4win

  • gpg4win

rpath

  • linux