REDHAT-BUG-2433480: Buffer Overflow
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2433480?
The severity of REDHAT-BUG-2433480 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2433480?
To fix REDHAT-BUG-2433480, upgrade GnuPG to version 2.5.17 or later.
What vulnerability does REDHAT-BUG-2433480 address?
REDHAT-BUG-2433480 addresses a buffer overflow vulnerability in gpg-agent during PKDECRYPT handling.
How can REDHAT-BUG-2433480 be exploited?
REDHAT-BUG-2433480 can be exploited by sending a crafted CMS EnvelopedData message with an oversized wrapped session key.
What is the potential impact of REDHAT-BUG-2433480?
The potential impact of REDHAT-BUG-2433480 includes denial of service and memory corruption.