Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-6169
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-6169

Description:
Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attackers to execute arbitrary code via messages with "C-escape" expansions, which cause the make_printable_string function to return a longer string than expected while constructing a prompt.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/30550

UBUNTU
  http://www.ubuntu.com/usn/usn-393-2
  http://www.ubuntu.com/usn/usn-389-1

TRUSTIX
  http://www.trustix.org/errata/2006/0068/

SUSE
  http://lists.suse.com/archive/suse-security-announce/2006-Dec/0004.html

ST
  1017291

SREASON
  http://securityreason.com/securityalert/1927

SGI

SAID
  Secunia Advisory: SA23284
  Secunia Advisory: SA23303
  Secunia Advisory: SA23299
  Secunia Advisory: SA23269
  Secunia Advisory: SA23250
  Secunia Advisory: SA23161
  Secunia Advisory: SA23146
  Secunia Advisory: SA23110
  Secunia Advisory: SA23171
  Secunia Advisory: SA23094
  Secunia Advisory: SA23513
  Secunia Advisory: SA24047

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0754.html

OPENPKG
  http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.037.html

MLIST
  http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000241.html

MISC

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:221

GENTOO
  http://security.gentoo.org/glsa/glsa-200612-03.xml

DEBIAN
  http://www.debian.org/security/2006/dsa-1231

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2007-047.htm

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/453253/100/100/threaded
  http://www.securityfocus.com/archive/1/archive/1/452829/100/0/threaded

BID
  21306


Return to the previous page.