10

CVE-2006-6235

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

Data is provided by the National Vulnerability Database (NVD)
GnuPrivacy Guard Version1.2.4
GnuPrivacy Guard Version1.2.5
GnuPrivacy Guard Version1.2.6
GnuPrivacy Guard Version1.2.7
GnuPrivacy Guard Version1.3.3
GnuPrivacy Guard Version1.3.4
GnuPrivacy Guard Version1.4
GnuPrivacy Guard Version1.4.1
GnuPrivacy Guard Version1.4.2
GnuPrivacy Guard Version1.4.2.1
GnuPrivacy Guard Version1.4.2.2
GnuPrivacy Guard Version1.4.3
GnuPrivacy Guard Version1.4.4
GnuPrivacy Guard Version1.4.5
GnuPrivacy Guard Version1.9.10
GnuPrivacy Guard Version1.9.15
GnuPrivacy Guard Version1.9.20
GnuPrivacy Guard Version2.0
GnuPrivacy Guard Version2.0.1
Gpg4winGpg4win Version1.0.7
RedhatEnterprise Linux Version4.0 Editionadvanced_server
RedhatEnterprise Linux Version4.0 Editionenterprise_server
RedhatEnterprise Linux Version4.0 Editionworkstation
RedhatFedora Core Versioncore_5.0
RedhatFedora Core Versioncore6
RedhatLinux Advanced Workstation Version2.1 Editionitanium_processor
RpathLinux Version1
SlackwareSlackware Linux Version11.0
UbuntuUbuntu Linux Version5.10
UbuntuUbuntu Linux Version6.06
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.9% 0.922
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C