>> GnuPG Duplicated User IDs Remote Memory Corruption Vulnerability
Title : GnuPG Duplicated User IDs Remote Memory Corruption Vulnerability VUPEN ID : VUPEN/ADV-2008-1056 CVE ID : CVE-2008-1530
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-01
Technical Description
A vulnerability has been identified in GnuPG, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by a memory corruption error when importing keys with duplicated user IDs, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into importing specially crafted keys.
Note: A NULL pointer dereference error, which occurs when importing certain keys from key servers, has also been reported.