CVE-2014-4617
Publication date 26 June 2014
Last updated 24 July 2024
Ubuntu priority
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Status
Package | Ubuntu Release | Status |
---|---|---|
gnupg | 14.04 LTS trusty |
Fixed 1.4.16-1ubuntu2.1
|
gnupg2 | 14.04 LTS trusty |
Fixed 2.0.22-3ubuntu1.1
|
Patch details
Package | Patch details |
---|---|
gnupg | |
gnupg2 |
References
Related Ubuntu Security Notices (USN)
- USN-2258-1
- GnuPG vulnerability
- 26 June 2014