CVE-2003-0255: Critical severity gnu privacy guard vulnerability
Published May 7, 2003
·Updated
The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.
Affected Software
1 affected component
GNU Privacy Guard<=1.2.1
Remediation
Patch Available
Event History
May 7, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
May 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0255?
CVE-2003-0255 has a medium severity rating due to improper key validation in GnuPG.
2
How do I fix CVE-2003-0255?
To fix CVE-2003-0255, upgrade GnuPG to version 1.2.2 or later.
3
Who is affected by CVE-2003-0255?
Users of GnuPG versions prior to 1.2.2 are affected by CVE-2003-0255.
4
What vulnerabilities does CVE-2003-0255 introduce?
CVE-2003-0255 introduces the risk of encrypting data without a trusted user ID, potentially compromising security.
5
Is a workaround available for CVE-2003-0255?
There is no recommended workaround for CVE-2003-0255; the best approach is to upgrade to a secure version.