积极预防 及时发现
快速响应 力保恢复
Gnu Privacy Guard (GnuPG, 就是gpg) 1.05 及其早期版本允许攻击者通...
发布时间:2001-08-14 信息来源:管理员

CNCVE编号:CNCVE-20010522 CVE编号:CAN-2001-0522 安全级别:中 漏洞中文描述: Gnu Privacy Guard (GnuPG, 就是gpg) 1.05 及其早期版本允许攻击者通过在恶意加密文件的格式字符串攻击来获得额外的权限。这个被使用的格式化字符串是原始的加密文件的名称。 漏洞英文描述: Gnu Privacy Guard (GnuPG, aka gpg) 1.05 and earlier can allow an attacker to gain additional privileges via a format string attack in a maliciously encrypted file. The format string used is the name of the original, encrypted file. 漏洞参考: Reference: BUGTRAQ:20010529 - GnuPG remote format string vulnerability Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0281.html Reference: CONFIRM:http://www.gnupg.org/whatsnew.html#rn20010529 Reference: MANDRAKE:M 系统类型:其他 漏洞类型:输入有效性检查错误