CVE-2006-6235

Description

A stack overwrite vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.898

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2006-6235 are affected in Gpg4win 1.0.7Windows
Vulnerabilities CVE-2003-0978,CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.3.3Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.5Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.6Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.2.7Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.3.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.1Windows
Vulnerabilities CVE-2006-0049,CVE-2006-0455,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.2Windows
Vulnerabilities CVE-2006-0049,CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.2.1Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.2.2Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.3Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.4Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.4.5Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.9.10Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.9.15Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 1.9.20Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 2.0Windows
Vulnerabilities CVE-2006-6235 are affected in GNU Privacy Guard (x64) 2.0.1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-348274Gpg4win (4.4.1)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)
PATCH-355070GNU Privacy Guard (x64) (2.5.16)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234