Unrated severityNVD Advisory· Published Dec 15, 2003· Updated Apr 16, 2026
CVE-2003-0971
CVE-2003-0971
Description
GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
Affected products
12cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:gnu:privacy_guard:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.3b:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- lists.gnupg.org/pipermail/gnupg-announce/2003q4/000276.htmlnvdPatchVendor Advisory
- lists.gnupg.org/pipermail/gnupg-announce/2003q4/000277.htmlnvdPatch
- www.securityfocus.com/bid/9115nvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/940388nvdUS Government Resource
- patches.sgi.com/support/free/security/advisories/20040202-01-U.ascnvd
- distro.conectiva.com.br/atualizacoes/nvd
- marc.infonvd
- secunia.com/advisories/10304nvd
- secunia.com/advisories/10349nvd
- secunia.com/advisories/10399nvd
- secunia.com/advisories/10400nvd
- www.debian.org/security/2004/dsa-429nvd
- www.mandriva.com/security/advisoriesnvd
- www.novell.com/linux/security/advisories/2003_048_gpg.htmlnvd
- www.redhat.com/support/errata/RHSA-2003-390.htmlnvd
- www.redhat.com/support/errata/RHSA-2003-395.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10982nvd
News mentions
0No linked articles in our index yet.