« Volver al listado

CVE-2001-0522

Estado: ModificadaAlta (7.5)—

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2001-0522",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2001-08-14T04:00:00.000",
  "references": [
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://online.securityfocus.com/archive/1/188218",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2001/dsa-061",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gnupg.org/whatsnew.html#rn20010529",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/403051",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/1845",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2001-073.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/2797",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/6642",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://online.securityfocus.com/archive/1/188218",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2001/dsa-061",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gnupg.org/whatsnew.html#rn20010529",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/403051",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/1845",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2001-073.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/2797",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/6642",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file."
    }
  ],
  "lastModified": "2026-06-16T21:54:27.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:privacy_guard:7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1DEE6D0-8097-4451-9699-F17FAE499578"
            },
            {
              "criteria": "cpe:2.3:a:gnu:privacy_guard:7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42ED2FF0-A7B9-45B2-845E-320084C1747D"
            },
            {
              "criteria": "cpe:2.3:a:gnu:privacy_guard:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "949ABA95-B06C-4398-AC26-1EC0D916DA69"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}