Vulnerability Description
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Privacy Guard | 1.2.4 |
| Gpg4Win | Gpg4Win | 1.0.7 |
| Redhat | Enterprise Linux | 4.0 |
| Redhat | Enterprise Linux Desktop | 3.0 |
| Redhat | Fedora Core | core_5.0 |
| Redhat | Linux Advanced Workstation | 2.1 |
| Rpath | Linux | 1 |
| Slackware | Slackware Linux | 11.0 |
| Ubuntu | Ubuntu Linux | 5.10 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20061201-01-P.asc
- http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000491.html
- http://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.html
- http://secunia.com/advisories/23245PatchVendor Advisory
- http://secunia.com/advisories/23250PatchVendor Advisory
- http://secunia.com/advisories/23255PatchVendor Advisory
- http://secunia.com/advisories/23259
- http://secunia.com/advisories/23269PatchVendor Advisory
- http://secunia.com/advisories/23284
- http://secunia.com/advisories/23290
- http://secunia.com/advisories/23299
- http://secunia.com/advisories/23303
- http://secunia.com/advisories/23329
- http://secunia.com/advisories/23335
- http://secunia.com/advisories/23513
FAQ
What is CVE-2006-6235?
CVE-2006-6235 is a vulnerability with a CVSS score of 10.0 (HIGH). A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to...
How severe is CVE-2006-6235?
CVE-2006-6235 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-6235?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Privacy Guard, Gpg4Win Gpg4Win, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Fedora Core.