peter bassill · operator
$ cve CVE-2001-0522 JSON

CVE-2001-0522 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.7% (pctl 96)

Patch early

A public exploit exists.

Description

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.73% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2001-08-14
Last modified2026-06-16

Affected (1)

VendorProduct
gnuprivacy guard

Public exploits

SourceTitleDate
exploit-dbGNU Privacy Guard 1.0.x - Format String2001-05-29

References

→ the Explorer  ·  watch your stack  ·  NVD