The vendor explicitly identifies these products as affected by this CVE.
- gnupg2 as a component of Red Hat Enterprise Linux 6
- gnupg2-smime as a component of Red Hat Enterprise Linux 6
- gnupg2.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in GnuPG. An attacker can provide crafted input to the `armor_filter` function, which incorrectly increments an index variable, leading to an out-of-bounds write. This memory corruption vulnerability may allow for information disclosure and could potentially lead to arbitrary code execution.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
