CVE-2010-2547
05.08.2010, 18:17
Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.Enginsight
Vendor | Product | Version |
---|---|---|
gnupg | gnupg | 2.0.0 ≤ 𝑥 ≤ 2.0.16 |
debian | debian_linux | 5.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References