CVE-2010-2547: Use After Free
Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2547?
CVE-2010-2547 has a medium severity, which can cause denial of service and potential arbitrary code execution.
How do I fix CVE-2010-2547?
To fix CVE-2010-2547, upgrade GnuPG to version 2.0.17 or later.
What software is affected by CVE-2010-2547?
CVE-2010-2547 affects GnuPG versions 2.0.0 through 2.0.16.
What type of vulnerability is CVE-2010-2547?
CVE-2010-2547 is a use-after-free vulnerability related to handling certificates.
Can CVE-2010-2547 lead to remote attacks?
Yes, CVE-2010-2547 can allow remote attackers to execute arbitrary code by exploiting the vulnerability.