MGASA-2016-0157
Dashboard / Vulnerabilities / MGASA-2016-0157
Summary: Updated pgpdump packages fix security vulnerability
Details: When pgpdump is run on specially crafted input, a denial of service condition occurs. The program runs with 100% CPU usage for an indefinite amount of time. A remote attacker is able to create a specially crafted input that is leading to CPU resource consumption resulting in denial of service (CVE-2016-4021).
References: https://advisories.mageia.org/MGASA-2016-0157.html, https://bugs.mageia.org/show_bug.cgi?id=18262, https://github.com/kazu-yamamoto/pgpdump/blob/master/CHANGES
Affected packages
Package
Name: pgpdump
Purl: pkg:rpm/mageia/pgpdump?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.30-1.mga5
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
