Heap
29-03-08, 00:28
GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1530)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1530)