CVE-2003-0978: High severity gnu privacy guard vulnerability
Published Dec 10, 2003
·Updated
Format string vulnerability in gpgkeyshkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.
Affected Software
6 affected components
GNU Privacy Guard=1.2.1
GNU Privacy Guard=1.3.3
GNU Privacy Guard=1.2.2-rc1
GNU Privacy Guard=1.2.2
GNU Privacy Guard=1.2.3
GNU Privacy Guard=1.2
Event History
Dec 10, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 5, 2004
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0978?
CVE-2003-0978 has a high severity rating due to its potential to cause denial of service and arbitrary code execution.
2
How do I fix CVE-2003-0978?
To fix CVE-2003-0978, upgrade to GnuPG versions 1.2.4 or later, or 1.3.4 or later.
3
Which versions of GnuPG are affected by CVE-2003-0978?
CVE-2003-0978 affects GnuPG versions 1.2.3 and earlier, as well as 1.3.3 and earlier.
4
What type of vulnerability is CVE-2003-0978?
CVE-2003-0978 is a format string vulnerability that can be exploited during key retrieval.
5
Can CVE-2003-0978 be exploited remotely?
Yes, CVE-2003-0978 can be exploited by remote attackers or malicious keyservers.