CVE-2012-6085

Description

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
2.306

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.1Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.13Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.14Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.15Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.16Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.6Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.7Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.2Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.17Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.18Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.19Windows
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.i386.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.x86_64.rpmLinux
Improper Input Validation Vulnerability (CVE-2012-6085)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234