CVE
- Id
- 3199
- CVE No.
- CVE-2001-0381
- Status
- Candidate
- Description
- The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.
- Phase
- Modified (20060915)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Oliver, Wall | REVIEWING(1) Ziese
- Comments
- Frech> XF:openpgp-private-key-disclosure(6558) | Christey> Consider CALDERA:CSSA-2001-017.0 | URL:http://www.caldera.com/support/security/advisories/CSSA-2001-017.0.txt | Also http://www.redhat.com/support/errata/RHSA-2001-063.html | Add that gnupg before 1.0.5-3 is affected. | TURBO:TLSA2001028 | http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html