积极预防 及时发现
快速响应 力保恢复
gpg (aka GnuPG) 1.0.4 及其其它版本不能正确地校验分离的数字签名, 这允许攻击者...
发布时间:2001-02-12 信息来源:管理员

CNCVE编号:CNCVE-20010071 CVE编号:CVE-2001-0071 安全级别:中 漏洞中文描述: gpg (aka GnuPG) 1.0.4 及其其它版本不能正确地校验分离的数字签名, 这允许攻击者改写文件内容而不被发现。 漏洞英文描述: gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection. 漏洞参考: REDHAT:RHSA-2000-131 MANDRAKE:MDKSA-2000-087 DEBIAN:DSA-010-1 XF:gnupg-detached-sig-modify CONECTIVA:CLA-2000:368 BID:2141 BUGTRAQ:20001220 Trustix Security Advisory - gnupg, ftpd-BSD 系统类型:其他 漏洞类型:其他