CVE-2016-4021 pgpdump: endless loop parsing specially crafted input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5733ad20f5 2016-05-10 11:45:44.977591 -------------------------------------------------------------------------------- Name : pgpdump Product : Fedora 23 Version : 0.30 Release : 1.fc23 URL : http://www.mew.org/~kazu/proj/pgpdump/ Summary : PGP packet visualizer Description : pgpdump is a PGP packet visualizer which displays the packet format of OpenPGP (RFC 4880) and PGP version 2 (RFC 1991). -------------------------------------------------------------------------------- Update Information: CVE-2016-4021 pgpdump: endless loop parsing specially crafted input -------------------------------------------------------------------------------- References: [ 1 ] Bug #1328351 - CVE-2016-4021 pgpdump: endless loop parsing specially crafted input https://bugzilla.redhat.com/show_bug.cgi?id=1328351 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pgpdump' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
CVE-2016-4021 pgpdump: endless loop parsing specially crafted input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-6fd7a31d36 2016-05-10 11:43:00.964428 -------------------------------------------------------------------------------- Name : pgpdump Product : Fedora 22 Version : 0.30 Release : 1.fc22 URL : http://www.mew.org/~kazu/proj/pgpdump/ Summary : PGP packet visualizer Description : pgpdump is a PGP packet visualizer which displays the packet format of OpenPGP (RFC 4880) and PGP version 2 (RFC 1991). -------------------------------------------------------------------------------- Update Information: CVE-2016-4021 pgpdump: endless loop parsing specially crafted input -------------------------------------------------------------------------------- References: [ 1 ] Bug #1328351 - CVE-2016-4021 pgpdump: endless loop parsing specially crafted input https://bugzilla.redhat.com/show_bug.cgi?id=1328351 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pgpdump' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
CVE-2016-4021 pgpdump: endless loop parsing specially crafted input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-8f4b54b005 2016-05-07 11:36:53.843242 -------------------------------------------------------------------------------- Name : pgpdump Product : Fedora 24 Version : 0.30 Release : 1.fc24 URL : http://www.mew.org/~kazu/proj/pgpdump/ Summary : PGP packet visualizer Description : pgpdump is a PGP packet visualizer which displays the packet format of OpenPGP (RFC 4880) and PGP version 2 (RFC 1991). -------------------------------------------------------------------------------- Update Information: CVE-2016-4021 pgpdump: endless loop parsing specially crafted input -------------------------------------------------------------------------------- References: [ 1 ] Bug #1328351 - CVE-2016-4021 pgpdump: endless loop parsing specially crafted input https://bugzilla.redhat.com/show_bug.cgi?id=1328351 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update pgpdump' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
The package pgpdump before version 0.30-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201604-11 ========================================= Severity: Low Date : 2016-04-22 CVE-ID : CVE-2016-4021 Package : pgpdump Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package pgpdump before version 0.30-1 is vulnerable to denial of service. Resolution ========= Upgrade to 0.30-1. # pacman -Syu "pgpdump> =0.30-1" The problem has been fixed upstream in version 0.30. Workaround ========= None. Description ========== When pgpdump is run on specially crafted input, a denial of service condition occurs. The program runs with 100% CPU usage for an indefinite amount of time. This can be abused in scenarios where users can supply input to pgpdump, e.g. in http://www.pgpdump.net/. Impact ===== A remote attacker is able to create a specially crafted input that is leading to CPU resource consumption resulting in denial of service. References ========= https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2016-030.txt https://www.cve.org/CVERecord?id=CVE-2016-4021 . Arch Linux Security Advisory ASA-202304-15: pgpdump versions earlier than 0.30-1 present a minor severity Denial of Service vulnerability, mandating an update.. Arch Linux Advisory, pgpdump Denial of Service, Linux Security Update. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.