Title : GnuPG "parse_comment()" Message Packet Length Handling Integer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-3123 CVE ID : CVE-2006-3746
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-02
Technical Description
A vulnerability has been identified in GnuPG, which may be exploited by attackers to execute arbitrary commands or cause a denial of service. This flaw is due to an integer overflow error in the "parse_comment()" function that does not properly handle a malformed message packet, which could be exploited by attackers to crash a vulnerable application or compromise an affected system.