Unrated severityNVD Advisory· Published Jan 5, 2004· Updated Apr 16, 2026
CVE-2003-0978
CVE-2003-0978
Description
Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.
Affected products
6cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gnu:privacy_guard:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:privacy_guard:1.3.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.