CVE-2014-4617

Priority
Medium
Description
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and
2.x before 2.0.24 allows context-dependent attackers to cause a denial of
service (infinite loop) via malformed compressed packets, as demonstrated
by an a3 01 5b ff byte sequence.
References
Bugs
Assigned-to
mdeslaur
Package
Upstream:released (2.0.24)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (2.0.17-2ubuntu2.12.04.4)
Ubuntu 13.10 (Saucy Salamander):released (2.0.20-1ubuntu3.1)
Ubuntu 14.04 LTS (Trusty Tahr):released (2.0.22-3ubuntu1.1)
Ubuntu 14.10 (Utopic Unicorn):released (2.0.24-1ubuntu1)
Patches:
Upstream:http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commitdiff;h=014b2103fcb1
Package
Source: gnupg (LP Ubuntu Debian)
Upstream:released (1.4.17,1.4.16-1.2)
Ubuntu 10.04 LTS (Lucid Lynx):released (1.4.10-2ubuntu1.6)
Ubuntu 12.04 LTS (Precise Pangolin):released (1.4.11-3ubuntu2.6)
Ubuntu 13.10 (Saucy Salamander):released (1.4.14-1ubuntu2.2)
Ubuntu 14.04 LTS (Trusty Tahr):released (1.4.16-1ubuntu2.1)
Ubuntu 14.10 (Utopic Unicorn):released (1.4.16-1.2ubuntu1)
Patches:
Upstream:http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commitdiff;h=11fdfcf82bd8
More Information

Valid XHTML 1.0 Strict

Updated: 2014-06-26 22:14:39 UTC (commit 8182)