CVE-2001-0522
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDMar 9
1st PoCMay 29
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20889⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01http://online.securityfocus.com/archive/1/188218https://exchange.xforce.ibmcloud.com/vulnerabilities/6642http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txthttp://www.debian.org/security/2001/dsa-061http://www.gnupg.org/whatsnew.html#rn20010529http://www.kb.cert.org/vuls/id/403051http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.htmlhttp://www.osvdb.org/1845http://www.redhat.com/support/errata/RHSA-2001-073.html