CVE-2006-6235: Critical severity GNU Privacy Guard vulnerability
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6235?
CVE-2006-6235 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2006-6235?
To remediate CVE-2006-6235, upgrade GnuPG to version 1.4.6 or later, or 2.0.2 or later.
Who is affected by CVE-2006-6235?
CVE-2006-6235 affects multiple versions of GnuPG including 1.x before 1.4.6 and 2.x before 2.0.2.
What type of attacks can exploit CVE-2006-6235?
CVE-2006-6235 can be exploited through specially crafted OpenPGP packets that trigger a stack overwrite.
Is CVE-2006-6235 still a concern today?
While CVE-2006-6235 is an older vulnerability, it remains a concern for systems that have not been updated.