CVE-2000-0445
CVSS 2.0 Score 2.1 of 10 (low)
Details
Summary
CVE-2000-0445 is a vulnerability affecting PGP 5.x on Unix systems. The pgpk command utilizes an insufficiently random data source for non-interactive key pair generation. Consequently, predictable keys may be produced, posing a risk to data security and confidentiality. Attackers could potentially leverage this issue to decrypt intercepted communications, or even impersonate individuals using the affected system. To mitigate this vulnerability, system administrators are advised to update their PGP installation or use a different randomness source for key generation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Pretty Good Privacy
Affected Vendors
- Broadcom