CVE-2016-4021
Publication date 26 May 2016
Last updated 18 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
From the Ubuntu Security Team
It was discovered that PGPdump incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pgpdump | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Vulnerable
|
|
| 14.04 LTS trusty |
Fixed 0.28-1+deb8u1build0.14.04.1
|
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H