CVE
- Id
- 45131
- CVE No.
- CVE-2010-2547
- Status
- Candidate
- Description
- Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its signature.
- Phase
- Assigned (20100630)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
492166 | 45131 | CVE-2010-2547 | MLIST:[gnupg-announce] 20100723 [Announce] Security Alert for GnuPG 2.0 - Realloc bug in GPGSM | View |
492167 | 45131 | CVE-2010-2547 | URL:http://lists.gnupg.org/pipermail/gnupg-announce/2010q3/000302.html | View |
492168 | 45131 | CVE-2010-2547 | CONFIRM:http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0076 | View |
492169 | 45131 | CVE-2010-2547 | CONFIRM:https://issues.rpath.com/browse/RPL-3229 | View |
492170 | 45131 | CVE-2010-2547 | DEBIAN:DSA-2076 | View |
492171 | 45131 | CVE-2010-2547 | URL:http://www.debian.org/security/2010/dsa-2076 | View |
492172 | 45131 | CVE-2010-2547 | FEDORA:FEDORA-2010-11413 | View |
492173 | 45131 | CVE-2010-2547 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2010-August/044935.html | View |
492174 | 45131 | CVE-2010-2547 | MANDRIVA:MDVSA-2010:143 | View |
492175 | 45131 | CVE-2010-2547 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2010:143 | View |
492176 | 45131 | CVE-2010-2547 | SLACKWARE:SSA:2010-240-01 | View |
492177 | 45131 | CVE-2010-2547 | URL:http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.462008 | View |
492178 | 45131 | CVE-2010-2547 | SUSE:SUSE-SR:2010:020 | View |
492179 | 45131 | CVE-2010-2547 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html | View |
492180 | 45131 | CVE-2010-2547 | BID:41945 | View |
492181 | 45131 | CVE-2010-2547 | URL:http://www.securityfocus.com/bid/41945 | View |
492182 | 45131 | CVE-2010-2547 | SECTRACK:1024247 | View |
492183 | 45131 | CVE-2010-2547 | URL:http://www.securitytracker.com/id?1024247 | View |
492184 | 45131 | CVE-2010-2547 | SECUNIA:38877 | View |
492185 | 45131 | CVE-2010-2547 | URL:http://secunia.com/advisories/38877 | View |
492186 | 45131 | CVE-2010-2547 | SECUNIA:40718 | View |
492187 | 45131 | CVE-2010-2547 | URL:http://secunia.com/advisories/40718 | View |
492188 | 45131 | CVE-2010-2547 | SECUNIA:40841 | View |
492189 | 45131 | CVE-2010-2547 | URL:http://secunia.com/advisories/40841 | View |
492190 | 45131 | CVE-2010-2547 | VUPEN:ADV-2010-1931 | View |
492191 | 45131 | CVE-2010-2547 | URL:http://www.vupen.com/english/advisories/2010/1931 | View |
492192 | 45131 | CVE-2010-2547 | VUPEN:ADV-2010-1950 | View |
492193 | 45131 | CVE-2010-2547 | URL:http://www.vupen.com/english/advisories/2010/1950 | View |
492194 | 45131 | CVE-2010-2547 | VUPEN:ADV-2010-1988 | View |
492195 | 45131 | CVE-2010-2547 | URL:http://www.vupen.com/english/advisories/2010/1988 | View |
492196 | 45131 | CVE-2010-2547 | VUPEN:ADV-2010-2217 | View |
492197 | 45131 | CVE-2010-2547 | URL:http://www.vupen.com/english/advisories/2010/2217 | View |
492198 | 45131 | CVE-2010-2547 | VUPEN:ADV-2010-3125 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
36139 | JVNDB-2010-001919 | Microsoft Windows の SMB サーバーにおけるサービス運用妨害 (DoS) の脆弱性 | Microsoft Windows の SMB サーバーには、SMB パケット内の内部変数の検証を適切に行わないため、サービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2010-2551 | 45131 | 7.8 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001919.html | View |