Vulnerability Description
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | Mageia | 3.0 |
| Debian | Debian Linux | 7.0 |
| Gnupg | Libksba | < 1.3.2 |
| Canonical | Ubuntu Linux | 12.04 |
| Gnupg | Gnupg | 2.1.0 |
Related Weaknesses (CWE)
References
- http://advisories.mageia.org/MGASA-2014-0498.htmlThird Party Advisory
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlMailing ListVendor Advisory
- http://secunia.com/advisories/60073Third Party Advisory
- http://secunia.com/advisories/60189Third Party Advisory
- http://secunia.com/advisories/60233Third Party Advisory
- http://www.debian.org/security/2014/dsa-3078Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:234Not Applicable
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:151Not Applicable
- http://www.securityfocus.com/bid/71285Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2427-1PatchThird Party Advisory
- https://blog.fuzzing-project.org/2-Buffer-overflow-and-other-minor-issues-in-GnuThird Party Advisory
- http://advisories.mageia.org/MGASA-2014-0498.htmlThird Party Advisory
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlMailing ListVendor Advisory
- http://secunia.com/advisories/60073Third Party Advisory
- http://secunia.com/advisories/60189Third Party Advisory
FAQ
What is CVE-2014-9087?
CVE-2014-9087 is a vulnerability with a CVSS score of 7.5 (HIGH). Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (...
How severe is CVE-2014-9087?
CVE-2014-9087 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9087?
Check the references section above for vendor advisories and patch information. Affected products include: Mageia Mageia, Debian Debian Linux, Gnupg Libksba, Canonical Ubuntu Linux, Gnupg Gnupg.