← Vulnerability feed

Vulnerability record · CVE-2006-3082 · published 19 June 2006

CVE-2006-3082: Gnupg vulnerability

Gnupg · Gnupg

parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.

5.0 CVSS 2.0 Medium EPSS 7.3% · top 5.8% CWE-189 · CWE-189
5.0CVSS 2.0 base score
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
66References
16 Jun 2026Last modified by NVD

Description

parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/trunk/g10/parse-packet.c?rev=4157&r1=4141&r2=4157
http://seclists.org/lists/fulldisclosure/2006/May/0774.html
http://seclists.org/lists/fulldisclosure/2006/May/0782.html
http://seclists.org/lists/fulldisclosure/2006/May/0789.html
http://secunia.com/advisories/20783 Vendor Advisory
http://secunia.com/advisories/20801 Vendor Advisory
http://secunia.com/advisories/20811 Vendor Advisory
http://secunia.com/advisories/20829 Vendor Advisory
http://secunia.com/advisories/20881 Vendor Advisory
http://secunia.com/advisories/20899 Vendor Advisory
http://secunia.com/advisories/20968 Vendor Advisory
http://secunia.com/advisories/21063 Vendor Advisory
http://secunia.com/advisories/21135 Vendor Advisory
http://secunia.com/advisories/21137 Vendor Advisory
http://secunia.com/advisories/21143 Vendor Advisory
http://secunia.com/advisories/21585 Vendor Advisory
http://securitytracker.com/id?1016519
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.457382
http://support.avaya.com/elmodocs2/security/ASA-2006-167.htm
http://www.debian.org/security/2006/dsa-1107
http://www.debian.org/security/2006/dsa-1115
http://www.mandriva.com/security/advisories?name=MDKSA-2006:110
http://www.novell.com/linux/security/advisories/2006_18_sr.html
http://www.novell.com/linux/security/advisories/2006_38_security.html
http://www.openpkg.com/security/advisories/OpenPKG-SA-2006.010.html
http://www.redhat.com/support/errata/RHSA-2006-0571.html
http://www.securityfocus.com/archive/1/438751/100/0/threaded
http://www.securityfocus.com/bid/18554 Vendor Advisory
http://www.vupen.com/english/advisories/2006/2450 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27245
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10089
https://usn.ubuntu.com/304-1/
ftp://patches.sgi.com/support/free/security/advisories/20060701-01-U
http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/trunk/g10/parse-packet.c?rev=4157&r1=4141&r2=4157
http://seclists.org/lists/fulldisclosure/2006/May/0774.html
http://seclists.org/lists/fulldisclosure/2006/May/0782.html
http://seclists.org/lists/fulldisclosure/2006/May/0789.html
http://secunia.com/advisories/20783 Vendor Advisory
http://secunia.com/advisories/20801 Vendor Advisory

Track CVE-2006-3082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24881Gnupg stack-based buffer overflow vulnerabilityIn GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo…EPSS 1.8%9.8CVE-2022-3515Gnupg libksba integer overflow vulnerabilityA vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for co…EPSS 1.6%9.3CVE-2008-1530Gnupg vulnerabilityGnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate ke…EPSS 4.3%8.8CVE-2018-1000858Gnupg cross-site request forgery vulnerabilityGnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Infor…EPSS 1.0%8.1CVE-2010-2547Gnupg use after free vulnerabilityUse-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) a…EPSS 5.3%7.8CVE-2026-24882Gnupg stack-based buffer overflow vulnerabilityIn GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.EPSS 0.44%7.8CVE-2020-25125Gnupg classic buffer overflow vulnerabilityGnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an…EPSS 1.3%7.5CVE-2019-14855Gnupg inadequate encryption strength vulnerabilityA flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2006-3082), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.