8.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message …
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.
Affected products
- <2.5.17
Matching in nixpkgs
pkgs.gnupg24
Modern release of the GNU Privacy Guard, a GPL OpenPGP implementation
pkgs.pam_gnupg
Unlock GnuPG keys on login
pkgs.gnupg1compat
Modern release of the GNU Privacy Guard, a GPL OpenPGP implementation with symbolic links for gpg and gpgv
pkgs.gnupg-pkcs11-scd
Smart-card daemon to enable the use of PKCS#11 tokens with GnuPG
-
nixos-unstable pkcs11-scd-0.11.0
- nixpkgs-unstable pkcs11-scd-0.11.0
- nixos-unstable-small pkcs11-scd-0.11.0
-
nixos-25.11 pkcs11-scd-0.11.0
- nixpkgs-25.11-darwin pkcs11-scd-0.11.0
pkgs.phpExtensions.gnupg
PHP wrapper for GpgME library that provides access to GnuPG
pkgs.php81Extensions.gnupg
PHP wrapper for GpgME library that provides access to GnuPG
pkgs.php82Extensions.gnupg
PHP wrapper for GpgME library that provides access to GnuPG
pkgs.php83Extensions.gnupg
PHP wrapper for GpgME library that provides access to GnuPG
pkgs.php84Extensions.gnupg
PHP wrapper for GpgME library that provides access to GnuPG
pkgs.sequoia-chameleon-gnupg
Sequoia's reimplementation of the GnuPG interface
pkgs.perlPackages.GnuPGInterface
Supply object methods for interacting with GnuPG
pkgs.perl538Packages.GnuPGInterface
Supply object methods for interacting with GnuPG
pkgs.perl540Packages.GnuPGInterface
Supply object methods for interacting with GnuPG
pkgs.python312Packages.python-gnupg
API for the GNU Privacy Guard (GnuPG)
Package maintainers
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>
-
@stigtsp Stig Palmquist <stig@stig.io>
-
@matthiasbeyer Matthias Beyer <mail@beyermatthias.de>
-
@philandstuff Philip Potter <philip.g.potter@gmail.com>
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@talyz Kim Lindberger <kim.lindberger@gmail.com>
-
@piotrkwiecinski Piotr Kwiecinski <piokwiecinski+nixpkgs@gmail.com>
-
@drupol Pol Dellaiera <pol.dellaiera@protonmail.com>
-
@aanderse Aaron Andersen <aaron@fosslib.net>
-
@NickCao Nick Cao <nickcao@nichi.co>