Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-0971
Description:GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
Test IDs: 1.3.6.1.4.1.25623.1.0.52533   1.3.6.1.4.1.25623.1.0.52975   1.3.6.1.4.1.25623.1.0.54511   1.3.6.1.4.1.25623.1.0.54080   1.3.6.1.4.1.25623.1.0.53137   1.3.6.1.4.1.25623.1.0.51490   1.3.6.1.4.1.25623.1.0.50961   1.3.6.1.4.1.25623.1.0.53128  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-0971
BugTraq ID: 9115
http://www.securityfocus.com/bid/9115
Bugtraq: 20031127 GnuPG's ElGamal signing keys compromised (Google Search)
http://marc.info/?l=bugtraq&m=106995769213221&w=2
CERT/CC vulnerability note: VU#940388
http://www.kb.cert.org/vuls/id/940388
Conectiva Linux advisory: CLA-2003:798
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000798
Debian Security Information: DSA-429 (Google Search)
http://www.debian.org/security/2004/dsa-429
http://www.mandriva.com/security/advisories?name=MDKSA-2003:109
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982
RedHat Security Advisories: RHSA-2003:390
http://www.redhat.com/support/errata/RHSA-2003-390.html
RedHat Security Advisories: RHSA-2003:395
http://www.redhat.com/support/errata/RHSA-2003-395.html
http://secunia.com/advisories/10304
http://secunia.com/advisories/10349
http://secunia.com/advisories/10399
http://secunia.com/advisories/10400
SGI Security Advisory: 20040202-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040202-01-U.asc
SuSE Security Announcement: SuSE-SA:2003:048 (Google Search)
http://www.novell.com/linux/security/advisories/2003_048_gpg.html




© 1998-2024 E-Soft Inc. All rights reserved.