← Back to CVE List
Vulnerability Intelligence Report

CVE-2006-6235

A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:5.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
gnu privacy_guard 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.3.3, 1.3.4, 1.4, 1.4.1, 1.4.2, 1.4.2.1, 1.4.2.2, 1.4.3, 1.4.4, 1.4.5, 1.9.10, 1.9.15, 1.9.20, 2.0, 2.0.1
gpg4win gpg4win 1.0.7
redhat enterprise_linux 4.0
redhat enterprise_linux_desktop 3.0, 4.0
redhat fedora_core core_5.0, core6
redhat linux_advanced_workstation 2.1
rpath linux 1
slackware slackware_linux 11.0
ubuntu ubuntu_linux 5.10, 6.06

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.671%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2006-12-02T00:00:00
Published2006-12-07T11:00:00
Patch Date2006-12-06
Last Updated2024-08-07T20:19:35

LINK COPIED TO CLIPBOARD