CVE-2001-0265: Low severity PGP PGP vulnerability
Published Jun 18, 2001
·Updated
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.
Affected Software
2 affected components
PGP PGP<=7.0.3
PGP PGP=5
Remediation
Event History
Jun 18, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0265?
CVE-2001-0265 is considered a high severity vulnerability due to its potential to allow attackers to create files in arbitrary locations.
2
How do I fix CVE-2001-0265?
To fix CVE-2001-0265, upgrade to a version of PGP that is later than 7.0.3.
3
Which versions of PGP are affected by CVE-2001-0265?
CVE-2001-0265 affects PGP versions 7.0.3 and earlier, as well as version 5.
4
What type of attack does CVE-2001-0265 enable?
CVE-2001-0265 enables attackers to execute arbitrary file creation attacks via malformed ASCII armored files.
5
Is CVE-2001-0265 specific to any operating system?
Yes, CVE-2001-0265 specifically affects the Windows version of PGP.