Vulnerability CVE-2002-1284


Published: 2002-11-29   Modified: 2012-02-12

Description:
The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
KGPG -> KGPG 

 References:
http://devel-home.kde.org/~kgpg/bug.html
http://marc.info/?l=bugtraq&m=103702926611286&w=2
http://www.securityfocus.com/bid/6152
http://xforce.iss.net/xforce/xfdb/10629

Copyright 2024, cxsecurity.com

 

Back to Top