CVE-2014-4617

Description

The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
8.032

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.8Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.1Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.13Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.14Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.15Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.16Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.3Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.4Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.6Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.7Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.10Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.11Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.12Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.2Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.5Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.17Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.18Windows
Multiple Vulnerabilities are affected in GnuPG for windows 2.0.19Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.0.7Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.4Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.5Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.2.7Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.0Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.1Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.2Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.3Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.4Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.6Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.90Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.91Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.92Windows
Vulnerabilities CVE-2013-4242,CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.3.93Windows
Multiple Vulnerabilities are affected in GnuPG for windows 1.4.13Windows
Vulnerabilities CVE-2013-4402,CVE-2013-4576,CVE-2014-4617,CVE-2016-6313 are affected in GnuPG for windows 1.4.14Windows
Vulnerabilities CVE-2013-4402,CVE-2014-4617 are affected in GnuPG for windows 2.0.20Windows
Vulnerabilities CVE-2013-4402,CVE-2014-4617 are affected in GnuPG for windows 2.0.21Windows
Vulnerabilities CVE-2013-4576,CVE-2014-4617 are affected in GnuPG for windows 1.4.15Windows
Vulnerabilities CVE-2014-4617 are affected in GnuPG for windows 1.4.16Windows
Vulnerabilities CVE-2014-4617 are affected in GnuPG for windows 2.0.22Windows
Vulnerabilities CVE-2014-4617 are affected in GnuPG for windows 2.0.23Windows
GNU privacy guard - a free PGP replacement (USN-2258-1) gnupg_1.4.16-1ubuntu2.3_i386.debLinux
GNU privacy guard - a free PGP replacement (USN-2258-1) gnupg_1.4.16-1ubuntu2.3_amd64.debLinux
GNU privacy guard - a free PGP replacement (USN-2258-1) gnupg2_2.0.22-3ubuntu1.3_i386.debLinux
GNU privacy guard - a free PGP replacement (USN-2258-1) gnupg2_2.0.22-3ubuntu1.3_amd64.debLinux
gnupg2 security update(DSA-2968-1) gnupg2_2.1.11-7_i386.debLinux
Improper Input Validation Vulnerability (CVE-2014-4617)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234