A flaw was discovered in pgpdump. When pgpdump is run on specially crafted input, a Denial-of-Service condition occurs. The program runs with 100% CPU usage for an indefinite amount of time. External references: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2016-030.txt References: http://seclists.org/bugtraq/2016/Apr/99 Upstream fix: https://github.com/kazu-yamamoto/pgpdump/pull/16
Created pgpdump tracking bugs for this issue: Affects: fedora-all [bug 1328353] Affects: epel-6 [bug 1328354] Affects: epel-7 [bug 1328355]
pgpdump-0.30-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
pgpdump-0.30-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
pgpdump-0.30-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
pgpdump-0.31-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
pgpdump-0.31-1.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.