CVE-2003-0255

The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.
References
Link Resource
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000694
http://marc.info/?l=bugtraq&m=105215110111174&w=2
http://marc.info/?l=bugtraq&m=105301357425157&w=2
http://marc.info/?l=bugtraq&m=105311804129104&w=2
http://marc.info/?l=bugtraq&m=105362224514081&w=2
http://www.kb.cert.org/vuls/id/397604 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html
http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:061
http://www.osvdb.org/4947
http://www.redhat.com/support/errata/RHSA-2003-175.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2003-176.html
http://www.securityfocus.com/bid/7497
http://www.turbolinux.com/security/TLSA-2003-34.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/11930
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000694
http://marc.info/?l=bugtraq&m=105215110111174&w=2
http://marc.info/?l=bugtraq&m=105301357425157&w=2
http://marc.info/?l=bugtraq&m=105311804129104&w=2
http://marc.info/?l=bugtraq&m=105362224514081&w=2
http://www.kb.cert.org/vuls/id/397604 US Government Resource
http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html
http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:061
http://www.osvdb.org/4947
http://www.redhat.com/support/errata/RHSA-2003-175.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2003-176.html
http://www.securityfocus.com/bid/7497
http://www.turbolinux.com/security/TLSA-2003-34.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/11930
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:privacy_guard:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000694 - () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000694 -
References () http://marc.info/?l=bugtraq&m=105215110111174&w=2 - () http://marc.info/?l=bugtraq&m=105215110111174&w=2 -
References () http://marc.info/?l=bugtraq&m=105301357425157&w=2 - () http://marc.info/?l=bugtraq&m=105301357425157&w=2 -
References () http://marc.info/?l=bugtraq&m=105311804129104&w=2 - () http://marc.info/?l=bugtraq&m=105311804129104&w=2 -
References () http://marc.info/?l=bugtraq&m=105362224514081&w=2 - () http://marc.info/?l=bugtraq&m=105362224514081&w=2 -
References () http://www.kb.cert.org/vuls/id/397604 - US Government Resource () http://www.kb.cert.org/vuls/id/397604 - US Government Resource
References () http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html - () http://www.linuxsecurity.com/advisories/engarde_advisory-3258.html -
References () http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html - () http://www.linuxsecurity.com/advisories/gentoo_advisory-3266.html -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2003:061 - () http://www.mandriva.com/security/advisories?name=MDKSA-2003:061 -
References () http://www.osvdb.org/4947 - () http://www.osvdb.org/4947 -
References () http://www.redhat.com/support/errata/RHSA-2003-175.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2003-175.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2003-176.html - () http://www.redhat.com/support/errata/RHSA-2003-176.html -
References () http://www.securityfocus.com/bid/7497 - () http://www.securityfocus.com/bid/7497 -
References () http://www.turbolinux.com/security/TLSA-2003-34.txt - () http://www.turbolinux.com/security/TLSA-2003-34.txt -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/11930 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/11930 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A135 -

Information

Published : 2003-05-27 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0255

Mitre link : CVE-2003-0255

CVE.ORG link : CVE-2003-0255


JSON object : View

Products Affected

gnu

  • privacy_guard