CVE-2014-3564 vulnerability in GNU and Other Products
Published on October 20, 2014
Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."
Products Associated with CVE-2014-3564
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2014-3564 are published in these products:
Exploit Probability
EPSS
2.81%
Percentile
85.91%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.