CVE-2013-4402
Published: 7 October 2013
The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.
Priority
Status
Package | Release | Status |
---|---|---|
gnupg Launchpad, Ubuntu, Debian |
lucid |
Released
(1.4.10-2ubuntu1.4)
|
precise |
Released
(1.4.11-3ubuntu2.4)
|
|
quantal |
Released
(1.4.11-3ubuntu4.3)
|
|
raring |
Released
(1.4.12-7ubuntu1.2)
|
|
upstream |
Released
(1.4.15)
|
|
gnupg2 Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Released
(2.0.17-2ubuntu2.12.04.3)
|
|
quantal |
Released
(2.0.17-2ubuntu3.2)
|
|
raring |
Released
(2.0.19-2ubuntu1.1)
|
|
upstream |
Released
(2.0.22)
|