PublicDateAtUSN: 2015-02-16 Candidate: CVE-2015-1607 PublicDate: 2019-11-20 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1607 https://blog.fuzzing-project.org/5-Multiple-issues-in-GnuPG-found-through-keyring-fuzzing-TFPA-0012015.html https://ubuntu.com/security/notices/USN-2554-1 Description: kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges." Ubuntu-Description: Notes: Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=778577 (gnupg2) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=778652 (gnupg) Priority: low Discovered-by: Hanno Böck Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_gnupg2: upstream: http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=3627123dc8fdc551caca1c7944713fbf01feccf6 (2.0) upstream_gnupg2: released (2.0.27,2.0.26-5) lucid_gnupg2: ignored (reached end-of-life) precise_gnupg2: released (2.0.17-2ubuntu2.12.04.6) trusty_gnupg2: released (2.0.22-3ubuntu1.3) trusty/esm_gnupg2: DNE (trusty was released [2.0.22-3ubuntu1.3]) utopic_gnupg2: released (2.0.24-1ubuntu2.2) devel_gnupg2: released (2.0.26-6ubuntu1) Patches_gnupg: upstream: http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=57af33d9e7c9b20b413b96882e670e75a67a5e65 (1.4) upstream_gnupg: released (1.4.18-7) lucid_gnupg: released (1.4.10-2ubuntu1.8) precise_gnupg: released (1.4.11-3ubuntu2.9) trusty_gnupg: released (1.4.16-1ubuntu2.3) trusty/esm_gnupg: released (1.4.16-1ubuntu2.3) utopic_gnupg: released (1.4.16-1.2ubuntu1.2) devel_gnupg: not-affected (1.4.18-7ubuntu1)