CVE-2006-6235 PUBLISHED CVSS 10 CRITICAL

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

EPSS 8.90% · 92.5th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
8.90%
92.5th percentile

Affected Products

VendorProductVersions
ubuntuubuntu_linux6.06, 5.10
redhatlinux_advanced_workstation2.1
gpg4wingpg4win1.0.7
gnuprivacy_guard1.2.7, 1.3.3, 1.3.4
n/an/an/a
redhatfedora_corecore_5.0, core6
redhatenterprise_linux4.0, 4.0, 4.0
slackwareslackware_linux11.0
redhatenterprise_linux_desktop4.0, 3.0
rpathlinux1

Timeline

References

…and 16 more

Open in Interactive Console →