Boletines de Vulnerabilidades

DSA-3005 gpgme1.0 - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Tomáš Trnka discovered a heap-based buffer overflow within the gpgsmstatus handler of GPGME, a library designed to make access to GnuPGeasier for applications. An attacker could use this issue to cause anapplication using GPGME to crash (denial of service) or possibly toexecute arbitrary code.

More info:

https://www.debian.org/security/2014/dsa-3005

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3564 and DSA-3005.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-15

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT