[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-0366Date: (C)2005-05-02   (M)2023-12-22


The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1013166
BID-12529
OSVDB-13775
GLSA-200503-29
MDKSA-2005:057
SUSE-SR:2005:007
VU#303094
http://eprint.iacr.org/2005/033
http://eprint.iacr.org/2005/033.pdf
http://www.pgp.com/library/ctocorner/openpgp.html

CPE    1
cpe:/a:gnupg:gnupg
CWE    1
CWE-326

© SecPod Technologies