CVE-2000-0974: High severity gnu privacy guard vulnerability
Published Dec 19, 2000
·Updated
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
Affected Software
4 affected components
GNU Privacy Guard=1.0.3
GNU Privacy Guard=1.0
GNU Privacy Guard=1.0.2
GNU Privacy Guard=1.0.1
Remediation
Patch Available
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0974?
CVE-2000-0974 is considered a medium severity vulnerability due to the potential for content modification without detection.
2
How do I fix CVE-2000-0974?
To fix CVE-2000-0974, upgrade to a newer version of GnuPG that addresses this vulnerability.
3
What versions of GnuPG are affected by CVE-2000-0974?
CVE-2000-0974 affects GnuPG versions 1.0, 1.0.1, 1.0.2, and 1.0.3.
4
What is the impact of CVE-2000-0974?
The impact of CVE-2000-0974 is that attackers can modify the contents of all documents in a signed file except for the first one.
5
Is CVE-2000-0974 still relevant today?
While CVE-2000-0974 is an older vulnerability, it is still relevant for systems using the affected versions of GnuPG.