VYPR
Unrated severityNVD Advisory· Published Nov 29, 2002· Updated Apr 16, 2026

CVE-2002-1284

CVE-2002-1284

Description

The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.

Affected products

6
  • Kgpg/Kgpg6 versions
    cpe:2.3:a:kgpg:kgpg:0.6:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:kgpg:kgpg:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:kgpg:kgpg:0.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:kgpg:kgpg:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:kgpg:kgpg:0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:kgpg:kgpg:0.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:kgpg:kgpg:0.8.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.