GnuPG
cpe:2.3:a:gnu:privacy_guard:*:*:*:*:*:*:*, +1 more
- >= 2.5.13, < 2.5.17
A null pointer dereference vulnerability has been identified in GnuPG versions prior to 2.5.17. The issue arises when a signature packet length is excessively long, causing the 'parse_signature' function to incorrectly return a success status while leaving the signature data pointer null. This flaw leads to an application crash when the null value is processed by subsequent functions.
Exploitation of this vulnerability causes an application crash, creating a denial-of-service condition.
Users of GnuPG should update to version 2.5.17. For Gpg4win users, the update to version 5.0.1 is recommended. If an immediate update is not feasible, removing the 'gpgsm' or 'gpgsm.exe' binary can prevent the vulnerability from being triggered remotely.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.