{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2001-0522", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "20010601 The GnuPG format string bug (was: TSLSA-2001-0009 - GnuPG)", "refsource" : "BUGTRAQ", "url" : "http://online.securityfocus.com/archive/1/188218" }, { "name" : "http://www.gnupg.org/whatsnew.html#rn20010529", "refsource" : "CONFIRM", "url" : "http://www.gnupg.org/whatsnew.html#rn20010529" }, { "name" : "MDKSA-2001:053", "refsource" : "MANDRAKE", "url" : "http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3" }, { "name" : "CLA-2001:399", "refsource" : "CONECTIVA", "url" : "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000399" }, { "name" : "DSA-061", "refsource" : "DEBIAN", "url" : "http://www.debian.org/security/2001/dsa-061" }, { "name" : "IMNX-2001-70-023-01", "refsource" : "IMMUNIX", "url" : "http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-023-01" }, { "name" : "RHSA-2001:073", "refsource" : "REDHAT", "url" : "http://www.redhat.com/support/errata/RHSA-2001-073.html" }, { "name" : "CSSA-2001-020.0", "refsource" : "CALDERA", "url" : "http://www.calderasystems.com/support/security/advisories/CSSA-2001-020.0.txt" }, { "name" : "SuSE-SA:2001:020", "refsource" : "SUSE", "url" : "http://www.novell.com/linux/security/advisories/2001_020_gpg_txt.html" }, { "name" : "TLSA2001028", "refsource" : "TURBO", "url" : "http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html" }, { "name" : "VU#403051", "refsource" : "CERT-VN", "url" : "http://www.kb.cert.org/vuls/id/403051" }, { "name" : "2797", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/2797" }, { "name" : "1845", "refsource" : "OSVDB", "url" : "http://www.osvdb.org/1845" }, { "name" : "gnupg-tty-format-string(6642)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/6642" } ] } }