SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-0522

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

HIGH 7.5EPSS 13.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
13.73% probability · 96th percentile
CISA KEV
Not listed
Affected
gnu/privacy guard
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.