- Description
- Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:privacy_guard:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E1DEE6D0-8097-4451-9699-F17FAE499578"
},
{
"criteria": "cpe:2.3:a:gnu:privacy_guard:7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42ED2FF0-A7B9-45B2-845E-320084C1747D"
},
{
"criteria": "cpe:2.3:a:gnu:privacy_guard:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "949ABA95-B06C-4398-AC26-1EC0D916DA69"
}
],
"operator": "OR"
}
]
}
]