CVE-2014-4617: Input Validation
Published Jun 25, 2014
·Updated
The douncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
Affected Software
64 affected components
gnupg GnuPG=2.0
gnupg GnuPG=2.0.1
gnupg GnuPG=2.0.3
gnupg GnuPG=2.0.4
gnupg GnuPG=2.0.5
gnupg GnuPG=2.0.6
gnupg GnuPG=2.0.7
gnupg GnuPG=2.0.8
gnupg GnuPG=2.0.10
gnupg GnuPG=2.0.11
gnupg GnuPG=2.0.12
gnupg GnuPG=2.0.13
gnupg GnuPG=2.0.14
gnupg GnuPG=2.0.15
gnupg GnuPG=2.0.16
gnupg GnuPG=2.0.17
gnupg GnuPG=2.0.18
gnupg GnuPG=2.0.19
gnupg GnuPG=2.0.20
gnupg GnuPG=2.0.21
gnupg GnuPG=2.0.22
gnupg GnuPG=2.0.23
gnupg GnuPG<=1.4.16
gnupg GnuPG=1.0.0
gnupg GnuPG=1.0.1
gnupg GnuPG=1.0.2
gnupg GnuPG=1.0.3
gnupg GnuPG=1.0.4
gnupg GnuPG=1.0.5
gnupg GnuPG=1.0.6
gnupg GnuPG=1.0.7
gnupg GnuPG=1.2.0
gnupg GnuPG=1.2.1
gnupg GnuPG=1.2.2
gnupg GnuPG=1.2.3
gnupg GnuPG=1.2.4
gnupg GnuPG=1.2.5
gnupg GnuPG=1.2.6
gnupg GnuPG=1.2.7
gnupg GnuPG=1.3.0
gnupg GnuPG=1.3.1
gnupg GnuPG=1.3.2
gnupg GnuPG=1.3.3
gnupg GnuPG=1.3.4
gnupg GnuPG=1.3.6
gnupg GnuPG=1.3.90
gnupg GnuPG=1.3.91
gnupg GnuPG=1.3.92
gnupg GnuPG=1.3.93
gnupg GnuPG=1.4.0
gnupg GnuPG=1.4.2
gnupg GnuPG=1.4.3
gnupg GnuPG=1.4.4
gnupg GnuPG=1.4.5
gnupg GnuPG=1.4.8
gnupg GnuPG=1.4.10
gnupg GnuPG=1.4.11
gnupg GnuPG=1.4.12
gnupg GnuPG=1.4.13
gnupg GnuPG=1.4.14
gnupg GnuPG=1.4.15
Debian Debian Linux=7.0
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
Remediation
Event History
Jun 25, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4617?
The severity of CVE-2014-4617 is categorized as a denial of service vulnerability allowing infinite loops.
2
How do I fix CVE-2014-4617?
To fix CVE-2014-4617, upgrade GnuPG to version 1.4.17 or 2.0.24 or later.
3
Which versions of GnuPG are affected by CVE-2014-4617?
CVE-2014-4617 affects GnuPG versions 1.x before 1.4.17 and 2.x before 2.0.24.
4
What type of attack does CVE-2014-4617 enable?
CVE-2014-4617 enables a denial of service attack through context-dependent malformed compressed packets.
5
Where can I find more information regarding CVE-2014-4617?
More information regarding CVE-2014-4617 can be obtained from GnuPG's official announcement and commit logs.