Description: Tavis Ormandy has reported a vulnerability in GnuPG, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an error within the decryption of malformed OpenPGP messages. This can be exploited to corrupt memory when decrypting a specially crafted OpenPGP message.
Successful exploitation allows execution of arbitrary code.
The vulnerability is reported in versions prior to 1.4.6 and 2.0.2.
Solution: Update to a fixed version or apply patch.
GnuPG 1.4:
Update to version 1.4.6 or apply patch.
GnuPG 2.0:
Apply patch.
Provided and/or discovered by: Tavis Ormandy
Changelog: 2006-12-08: Updated link to vendor advisory.
2006-12-19: Added link to US-CERT.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.