Vulnerability Bulletins

DSA-3005 gpgme1.0 - security update

   
Affected software Debian
 
Tomáš Trnka discovered a heap-based buffer overflow within the gpgsmstatus handler of GPGME, a library designed to make access to GnuPGeasier for applications. An attacker could use this issue to cause anapplication using GPGME to crash (denial of service) or possibly toexecute arbitrary code.

More info:

https://www.debian.org/security/2014/dsa-3005