GnuPG External HKP Format String Vulnerability

BID:9144

Info

GnuPG External HKP Format String Vulnerability

Bugtraq ID: 9144
Class: Input Validation Error
CVE: CVE-2003-0978
Remote: Yes
Local: No
Published: Dec 03 2003 12:00AM
Updated: Jul 12 2009 12:56AM
Credit: Discovery of this issue is credited to Evgeny Legerov.
Vulnerable: Sun Cobalt RaQ XTR
Sun Cobalt Qube 3
GNU GNU Privacy Guard 1.3.3
GNU GNU Privacy Guard 1.2.3
+ Mandriva Linux Mandrake 9.2
+ Turbolinux Turbolinux Desktop 10.0
GNU GNU Privacy Guard 1.2.2 -rc1
+ S.u.S.E. Linux Personal 8.2
GNU GNU Privacy Guard 1.2.2 -r1
+ Gentoo Linux 1.4 _rc3
+ Gentoo Linux 1.4 _rc2
+ Gentoo Linux 1.4 _rc1
GNU GNU Privacy Guard 1.2.2
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Workstation 3.1.1
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
GNU GNU Privacy Guard 1.2.1
+ OpenPKG OpenPKG 1.2
+ Redhat Linux 9.0 i386
+ Terra Soft Solutions Yellow Dog Linux 3.0
GNU GNU Privacy Guard 1.2
Not Vulnerable: GNU GNU Privacy Guard 1.3.4

Discussion

GnuPG External HKP Format String Vulnerability

GnuPG is prone to a remotely exploitable format string vulnerability in the external HKP interface (which is not typically enabled by default in stable versions). This is due to incorrect usage of fprintf(), potentially allowing a malicious HKP keyserver to execute arbitrary code on a system running the vulnerable software.

Exploit / POC

GnuPG External HKP Format String Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

GnuPG External HKP Format String Vulnerability

Solution:
Sun have released fixes to address this issue in Sun Cobalt RaQ XTR and Qube 3 products. Fixes are linked below.

SuSE has released an advisory (SuSE-SA:2003:048) that includes fixes for this issue. Please see the attached advisory for details on obtaining and applying fixes.

The vendor has addressed this issue in CVS for the 1.2 stable branch. Version 1.3.4 was also released to address this issue in the 1.3 development branch.

Gentoo has released an advisory (200312-05) to address this issue. All Gentoo Linux systems should be updated to use gnupg-1.2.3-r5 or higher as follows:

emerge sync
emerge -pv '>=app-crypt/gnupg-1.2.3-r5'
emerge '>=app-crypt/gnupg-1.2.3-r5'
emerge clean


Sun Cobalt Qube 3

Sun Cobalt RaQ XTR

GNU GNU Privacy Guard 1.2.2

GNU GNU Privacy Guard 1.2.2 -rc1

References

GnuPG External HKP Format String Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report