CVE-2003-0971

CWE-4226 documents6 sources
Severity
5.0MEDIUM
EPSS
2.3%
top 15.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15
Latest updateMay 3

Description

GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDgnu/privacy_guard11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3rmj-3mrh-fv5j: GnuPG (GPG) 12022-05-03
CVEList
CVE-2003-0971: GnuPG (GPG) 12003-12-02

📋Vendor Advisories

1
Red Hat
security flaw2003-11-27

📐Framework References

1
CWE
Unprotected Windows Messaging Channel ('Shatter')

💬Community

1
Bugzilla
CVE-2003-0971 security flaw2018-08-16
CVE-2003-0971 (MEDIUM CVSS 5) | GnuPG (GPG) 1.0.2 | cvebase.io