{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2019-11-20T19:15:11Z",
  "id": "CVE-2015-1606",
  "details": "The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2015/dsa-3184"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2015/02/13/14"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2015/02/14/6"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securitytracker.com/id/1031876"
    },
    {
      "type": "ADVISORY",
      "url": "https://blog.fuzzing-project.org/5-Multiple-issues-in-GnuPG-found-through-keyring-fuzzing-TFPA-0012015.html"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2015/02/13/14"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2015/02/14/6"
    },
    {
      "type": "WEB",
      "url": "http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git%3Ba=commit%3Bh=f0f71a721ccd7ab9e40b8b6b028b59632c0cc648"
    }
  ]
}
