PT-2001-1502 · Pine+1 · Pgp4Pine+1
Published
2001-04-04
·
Updated
2017-07-11
·
CVE-2001-0273
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pgp4pine Pine/PGP interface version 1.75-6
Description
The issue arises from the improper checking of public key expiration when obtaining keys via Gnu Privacy Guard (GnuPG), resulting in messages being sent in cleartext.
Recommendations
For pgp4pine Pine/PGP interface version 1.75-6, consider updating the key management process to properly handle public key expiration checks to prevent messages from being sent in cleartext.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnupg
Pgp4Pine