9.3
CVSSv2

CVE-2008-1530

Published: 27/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

GnuPG (gpg) 1.4.8 and 2.0.8 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."

Vulnerable Product Search on Vulmon Subscribe to Product

gnupg gnupg 1.4.8

gnupg gnupg 2.0.8

Vendor Advisories

Debian Bug report logs - #472928 gnupg2: CVE-2008-1530 memory corruption via crafted key file Package: gnupg2; Maintainer for gnupg2 is Debian GnuPG Maintainers <pkg-gnupg-maint@listsaliothdebianorg>; Source for gnupg2 is src:gnupg2 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, ...