CVE-2014-9087
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.17% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-191
- Affected
- mageia/mageia · debian/debian linux · gnupg/libksba · canonical/ubuntu linux · gnupg/gnupg
- Source
- security@debian.org
References
- http://advisories.mageia.org/MGASA-2014-0498.htmlThird Party Advisory
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlMailing List, Vendor Advisory
- http://secunia.com/advisories/60073Third Party Advisory
- http://secunia.com/advisories/60189Third Party Advisory
- http://secunia.com/advisories/60233Third Party Advisory
- http://www.debian.org/security/2014/dsa-3078Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:234Not Applicable
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:151Not Applicable
- http://www.securityfocus.com/bid/71285Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2427-1Patch, Third Party Advisory
- https://blog.fuzzing-project.org/2-Buffer-overflow-and-other-minor-issues-in-GnuPG-and-libksba-TFPA-0012014.htmlThird Party Advisory
- http://advisories.mageia.org/MGASA-2014-0498.htmlThird Party Advisory
- http://lists.gnupg.org/pipermail/gnupg-announce/2014q4/000359.htmlMailing List, Vendor Advisory
- http://secunia.com/advisories/60073Third Party Advisory
- http://secunia.com/advisories/60189Third Party Advisory
- http://secunia.com/advisories/60233Third Party Advisory
- http://www.debian.org/security/2014/dsa-3078Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:234Not Applicable
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:151Not Applicable
- http://www.securityfocus.com/bid/71285Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2427-1Patch, Third Party Advisory
- https://blog.fuzzing-project.org/2-Buffer-overflow-and-other-minor-issues-in-GnuPG-and-libksba-TFPA-0012014.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.