CVE-2001-0522: High severity gnu privacy guard vulnerability
Published Aug 14, 2001
·Updated
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
Affected Software
3 affected components
GNU Privacy Guard=7.1
GNU Privacy Guard=7.2
GNU Privacy Guard=8.0
Remediation
Event History
Aug 14, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0522?
CVE-2001-0522 is considered a medium severity vulnerability due to the potential privilege escalation it poses.
2
How do I fix CVE-2001-0522?
To fix CVE-2001-0522, you should update Gnu Privacy Guard to version 1.06 or later.
3
What software is affected by CVE-2001-0522?
CVE-2001-0522 affects Gnu Privacy Guard versions 1.05 and earlier.
4
What type of vulnerability is CVE-2001-0522?
CVE-2001-0522 is a format string vulnerability that could be exploited through manipulated filenames in encrypted files.
5
What can an attacker gain by exploiting CVE-2001-0522?
An attacker exploiting CVE-2001-0522 can potentially gain elevated privileges on a target system.