CVE-2003-0255
Summary
| CVE | CVE-2003-0255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-05-27 04:00:00 UTC |
| Updated | 2018-05-03 01:29:00 UTC |
| Description | The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Privacy Guard | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| LinuxSecurity.com: Gentoo: gnupg key validation bug | MISC | www.linuxsecurity.com | |
| '[slackware-security] GnuPG key validation fix (SSA:2003-141-04)' - MARC | BUGTRAQ | marc.info | |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | |
| '[ESA-20030515-016] 'gnupg' key validation bug.' - MARC | ENGARDE | marc.info | |
| Mandriva Security Advisories | MANDRAKE | www.mandriva.com | |
| Home - Conectiva | CONECTIVA | distro.conectiva.com.br | |
| CERT/CC Vulnerability Note VU#397604 | CERT-VN | www.kb.cert.org | US Government Resource |
| 4947 | OSVDB | www.osvdb.org | |
| GNU Privacy Guard Insecure Trust Path To User ID Weakness | BID | www.securityfocus.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| redhat.com | Red Hat Support | REDHAT | www.redhat.com | Patch, Vendor Advisory |
| 'Key validity bug in GnuPG 1.2.1 and earlier' - MARC | BUGTRAQ | marc.info | |
| 404 Not Found | TURBO | www.turbolinux.com | |
| LinuxSecurity.com: EnGarde: 'gnupg' key validation bug | ENGARDE | www.linuxsecurity.com | |
| '[OpenPKG-SA-2003.029] OpenPKG Security Advisory (gnupg)' - MARC | BUGTRAQ | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.