Vulnerabilities > CVE-2001-0072 - Unspecified vulnerability in GNU Privacy Guard
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN gnu
nessus
Summary
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2000-087.NASL |
description | When importing keys from public key servers, GnuPG will import private keys (also known as secret keys) in addition to public keys. If this happens, the user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 61873 |
published | 2012-09-06 |
reporter | This script is Copyright (C) 2012-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/61873 |
title | Mandrake Linux Security Advisory : gnupg (MDKSA-2000:087) |
code |
|
Redhat
advisories |
|
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000368
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000368
- http://www.debian.org/security/2000/20001225b
- http://www.debian.org/security/2000/20001225b
- http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3
- http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3
- http://www.osvdb.org/1702
- http://www.osvdb.org/1702
- http://www.redhat.com/support/errata/RHSA-2000-131.html
- http://www.redhat.com/support/errata/RHSA-2000-131.html
- http://www.securityfocus.com/archive/1/152197
- http://www.securityfocus.com/archive/1/152197
- http://www.securityfocus.com/bid/2153
- http://www.securityfocus.com/bid/2153
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5803