Releases1
Last Release
GNU privacy guard - a free PGP replacement

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
>= 2.5.13, < 2.5.178.1 HIGH

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that could lead to remote code execution.

>= 2.5.13, < 2.5.178.4 HIGH

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

>= 2.5.13, < 2.5.173.7 LOW

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).