Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GnuPG External HKP Format String Vulnerability

GnuPG is prone to a remotely exploitable format string vulnerability in the external HKP interface (which is not typically enabled by default in stable versions). This is due to incorrect usage of fprintf(), potentially allowing a malicious HKP keyserver to execute arbitrary code on a system running the vulnerable software.







 

Privacy Statement
Copyright 2009, SecurityFocus