CVE-2013-4402

Description

The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.702

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.1Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.13Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.14Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.15Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.16Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.2Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.17Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.18Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.19Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.13Windows
Vulnerabilities CVE-2013-4402,CVE-2013-4576,CVE-2014-4617,CVE-2016-6313 are affected in GnuPG for windows 1.4.14Windows
Vulnerabilities CVE-2013-4402,CVE-2014-4617 are affected in GnuPG for windows 2.0.20Windows
Vulnerabilities CVE-2013-4402,CVE-2014-4617 are affected in GnuPG for windows 2.0.21Windows
gnupg2 security update(DSA-2968-1) gnupg2_2.0.19-2+deb7u2_i386.debLinux
gnupg2 security update(DSA-2968-1) gnupg2_2.0.19-2+deb7u2_amd64.debLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.i386.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.10-6.el5_10.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-2.0.14-6.el6_4.x86_64.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.i686.rpmLinux
(RHSA-2013:1459) Moderate: gnupg2 security update gnupg2-smime-2.0.14-6.el6_4.x86_64.rpmLinux
Improper Input Validation Vulnerability (CVE-2013-4402)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234