Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2001-0072

Опубликовано: 12 фев. 2001
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:privacy_guard:1.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:privacy_guard:1.0.3b:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.0096
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

redhat
больше 24 лет назад

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

github
около 3 лет назад

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

EPSS

Процентиль: 75%
0.0096
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other