Описание
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
Дополнительная информация
https://bugzilla.redhat.com/show_bug.cgi?id=1616565security flaw
EPSS
Процентиль: 78%
0.01969
Низкий
Связанные уязвимости
nvd
больше 25 лет назад
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
github
больше 4 лет назад
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
EPSS
Процентиль: 78%
0.01969
Низкий