CLA-2001:399Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000399 CVE-2001-0522
GNU Privacy Guard 1.0.x - Format String
Record summary
CVE-2001-0522 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU Privacy Guard 1.0.x - Format StringExploitDB exploitby fish stiqzNot analyzed1 file
References
Showing 12 of 15IMNX-2001-70-023-01Vendor advisory
http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01 20010601 The GnuPG format string bug (was: TSLSA-2001-0009 - GnuPG)mailing list
http://online.securityfocus.com/archive/1/188218 CSSA-2001-020.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt DSA-061Vendor advisory
http://www.debian.org/security/2001/dsa-061 gnupg.orgConfirmation
http://www.gnupg.org/whatsnew.html VU#403051Third-party advisory
http://www.kb.cert.org/vuls/id/403051 MDKSA-2001:053Vendor advisory
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3 SuSE-SA:2001:020Vendor advisory
http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html 1845vdb entry
http://www.osvdb.org/1845 RHSA-2001:073Vendor advisory
http://www.redhat.com/support/errata/RHSA-2001-073.html 2797vdb entry
http://www.securityfocus.com/bid/2797