CVE-2001-0072
Summary
| CVE | CVE-2001-0072 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-02-12 05:00:00 UTC |
| Updated | 2017-10-10 01:29:00 UTC |
| Description | gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Privacy Guard | 1.0 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.1 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.2 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.3 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.3b | All | All | All |
| Application | Gnu | Privacy Guard | 1.0 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.1 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.2 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.3 | All | All | All |
| Application | Gnu | Privacy Guard | 1.0.3b | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Home - Conectiva | CONECTIVA | distro.conectiva.com.br | |
| 504 Gateway Time-out | BID | www.securityfocus.com | Patch, Vendor Advisory |
| 1702 | OSVDB | www.osvdb.org | |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| Debian GNU/Linux -- Security Information -- DSA-010-1 gnupg | DEBIAN | www.debian.org | |
| Linux Mandrake | MANDRAKE | www.linux-mandrake.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.