CVE-2006-3746: Integer Overflow
Published Jul 28, 2006
·Updated
Integer overflow in parsecomment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.
Affected Software
1 affected component
gnupg GnuPG=1.4.4
Event History
Jul 28, 2006
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3746?
CVE-2006-3746 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-3746?
To fix CVE-2006-3746, upgrade to a later version of GnuPG that is not affected by this vulnerability.
3
Which versions of GnuPG are affected by CVE-2006-3746?
GnuPG version 1.4.4 is specifically affected by CVE-2006-3746.
4
What type of attack does CVE-2006-3746 facilitate?
CVE-2006-3746 allows remote attackers to cause a denial of service through a crafted message.
5
How can the impact of CVE-2006-3746 be mitigated?
To mitigate the impact of CVE-2006-3746, users should avoid processing untrusted or malformed messages with the vulnerable software.