Executive Summary
Summary | |
---|---|
Title | Updated gnupg packages fix validation bug |
Informations | |||
---|---|---|---|
Name | RHSA-2003:176 | First vendor Publication | 2003-06-23 |
Vendor | RedHat | Last vendor Modification | 2003-06-23 |
Severity (Vendor) | N/A | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2003-176.html |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:135 | |||
Oval ID: | oval:org.mitre.oval:def:135 | ||
Title: | GnuPG Invalid User ID Vulnerability | ||
Description: | The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2003-0255 | Version: | 2 |
Platform(s): | Red Hat Linux 9 | Product(s): | GnuPG |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
4947 | GnuPG Multiple Userid Key Validity GnuPG versions prior to 1.2.2 handle trust relationships of multiple userids bound to a single key incorrectly. If a key has more than one userid, all userids assume the validity of the most valid userid, rather than applying the relevant trust path to each userid individually. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-07-31 | Name : The remote Mandrake Linux host is missing a security update. File : mandrake_MDKSA-2003-061.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2003-176.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:48:09 |
|