Date: Fri, 23 Jul 2010 21:02:37 +0200 From: Florian Weimer <fw@...eb.enyo.de> To: oss-security@...ts.openwall.com Subject: CVE request: GnuPG 2 GnuPG 2.0 before version 2.0.17 reuses a freed pointer when verifying a signature or importing a certificate with many Subject Alternate Names, possibly allowing context-dependent attacks to execute arbitrary code. <http://lists.gnupg.org/pipermail/gnupg-announce/2010q3/000302.html>
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.