CVE-2001-0071: Low severity gnu privacy guard vulnerability
Published Feb 12, 2001
·Updated
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.
Affected Software
5 affected components
GNU Privacy Guard=1.0
GNU Privacy Guard=1.0.1
GNU Privacy Guard=1.0.2
GNU Privacy Guard=1.0.3
GNU Privacy Guard=1.0.3b
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 12, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0071?
CVE-2001-0071 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2001-0071?
To fix CVE-2001-0071, upgrade GnuPG to version 1.0.4 or later, where the issue is addressed.
3
What types of attacks are possible due to CVE-2001-0071?
CVE-2001-0071 can allow attackers to modify the contents of a file undetected.
4
Which versions of GnuPG are affected by CVE-2001-0071?
CVE-2001-0071 affects GnuPG versions 1.0 through 1.0.3b.
5
Is CVE-2001-0071 still relevant today?
CVE-2001-0071 is mostly considered outdated but could still pose a risk if legacy systems are in use.