CVE-2016-4021: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
Affected products
- Fedoraproject Fedora: version 22 only; version 23 only; version 24 only
- Pgpdump Project Pgpdump: up to and including 0.29
Published 2016-05-26. Last modified 2026-06-17.