CVE-2001-0522
UnknownEPSS 13.73%
Last modified
CVE-2001-0522 is a vulnerability of currently unknown severity. Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.. EPSS estimates a 13.73% chance of exploitation in the next 30 days.
Description
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Privacy Guard | 7.1 |
| Gnu | Privacy Guard | 7.2 |
| Gnu | Privacy Guard | 8.0 |
References
- http://www.kb.cert.org/vuls/id/403051US Government Resource
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/403051US Government Resource
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-053.php3Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0522?
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
How severe is CVE-2001-0522?
Severity scoring for CVE-2001-0522 is pending analysis. The EPSS model estimates a 13.73% probability of exploitation in the next 30 days.
How do I fix CVE-2001-0522?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2001
- CVE-2001-0516Oracle listener between Oracle 9i and Oracle 8.0 allows remo…
- CVE-2001-0517Oracle listener in Oracle 8i on Solaris allows remote attack…
- CVE-2001-0518Oracle listener before Oracle 9i allows attackers to cause a…
- CVE-2001-0519Aladdin eSafe Gateway versions 2.x allows a remote attacker …
- CVE-2001-0520Aladdin eSafe Gateway versions 3.0 and earlier allows a remo…
- CVE-2001-0521Aladdin eSafe Gateway versions 3.0 and earlier allows a remo…
- CVE-2001-0523eEye SecureIIS versions 1.0.3 and earlier allows a remote at…
- CVE-2001-0524eEye SecureIIS versions 1.0.3 and earlier does not perform l…
- CVE-2001-0525Buffer overflow in dsh in dqs 3.2.7 in SuSE Linux 7.0 and ea…
- CVE-2001-0526Buffer overflow in the Xview library as used by mailtool in …
- CVE-2001-0527DCScripts DCForum versions 2000 and earlier allow a remote a…
- CVE-2001-0528Oracle E-Business Suite Release 11i Applications Desktop Int…
Are you affected by CVE-2001-0522?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
