{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "heap-based buffer overflow in gpgsm status handler",
    "tracking": {
      "current_release_date": "2026-07-27T09:11:41+00:00",
      "generator": {
        "date": "2026-07-27T09:11:41+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2014-3564",
      "initial_release_date": "2014-07-30T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-27T09:11:41+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gpgme",
            "product": {
              "name": "gpgme",
              "product_id": "gpgme",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gpgme"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gpgme-debuginfo",
            "product": {
              "name": "gpgme-debuginfo",
              "product_id": "gpgme-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gpgme-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gpgme-devel",
            "product": {
              "name": "gpgme-devel",
              "product_id": "gpgme-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gpgme-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gpgme",
            "product": {
              "name": "gpgme",
              "product_id": "gpgme.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gpgme?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:gpgme"
        },
        "product_reference": "gpgme",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:gpgme"
        },
        "product_reference": "gpgme",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:gpgme-debuginfo"
        },
        "product_reference": "gpgme-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:gpgme-debuginfo"
        },
        "product_reference": "gpgme-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme-devel as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:gpgme-devel"
        },
        "product_reference": "gpgme-devel",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme-devel as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:gpgme-devel"
        },
        "product_reference": "gpgme-devel",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:gpgme.src"
        },
        "product_reference": "gpgme.src",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gpgme.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:gpgme.src"
        },
        "product_reference": "gpgme.src",
        "relates_to_product_reference": "rhel-7-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-3564",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "discovery_date": "2014-06-25T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:gpgme-debuginfo",
            "rhel-6-els.els:gpgme-devel",
            "rhel-7-els.els:gpgme-debuginfo",
            "rhel-7-els.els:gpgme-devel"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to \"different line lengths in a specific order.\"",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-6-els.els:gpgme",
          "rhel-6-els.els:gpgme.src",
          "rhel-7-els.els:gpgme",
          "rhel-7-els.els:gpgme.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:gpgme-debuginfo",
          "rhel-6-els.els:gpgme-devel",
          "rhel-7-els.els:gpgme-debuginfo",
          "rhel-7-els.els:gpgme-devel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-3564"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3564"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-3564"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-6-els.els:gpgme",
            "rhel-6-els.els:gpgme.src",
            "rhel-7-els.els:gpgme",
            "rhel-7-els.els:gpgme.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
            "baseScore": 5.1
          },
          "products": [
            "rhel-6-els.els:gpgme",
            "rhel-6-els.els:gpgme-debuginfo",
            "rhel-6-els.els:gpgme-devel",
            "rhel-6-els.els:gpgme.src",
            "rhel-7-els.els:gpgme",
            "rhel-7-els.els:gpgme-debuginfo",
            "rhel-7-els.els:gpgme-devel",
            "rhel-7-els.els:gpgme.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "rhel-6-els.els:gpgme",
            "rhel-6-els.els:gpgme-debuginfo",
            "rhel-6-els.els:gpgme-devel",
            "rhel-6-els.els:gpgme.src",
            "rhel-7-els.els:gpgme",
            "rhel-7-els.els:gpgme-debuginfo",
            "rhel-7-els.els:gpgme-devel",
            "rhel-7-els.els:gpgme.src"
          ]
        }
      ],
      "title": "heap-based buffer overflow in gpgsm status handler"
    }
  ]
}