{"id":"CVE-2008-1530","details":"GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers \"memory corruption around deduplication of user IDs.\"","modified":"2026-04-10T03:39:46.302179Z","published":"2008-03-27T23:44:00Z","related":["openSUSE-SU-2024:10815-1"],"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/29568"},{"type":"ADVISORY","url":"http://www.ocert.org/advisories/ocert-2008-1.html"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2008/1056/references"},{"type":"WEB","url":"http://lists.gnupg.org/pipermail/gnupg-announce/2008q1/000272.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/28487"},{"type":"WEB","url":"https://bugs.g10code.com/gnupg/issue894"},{"type":"WEB","url":"https://bugs.gentoo.org/show_bug.cgi?id=214990"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41547"}],"schema_version":"1.7.5"}