CVE-2000-0445

CVSS 2.0 Score 2.1 of 10 (low)

Details

Published May 24, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0445 is a vulnerability affecting PGP 5.x on Unix systems. The pgpk command utilizes an insufficiently random data source for non-interactive key pair generation. Consequently, predictable keys may be produced, posing a risk to data security and confidentiality. Attackers could potentially leverage this issue to decrypt intercepted communications, or even impersonate individuals using the affected system. To mitigate this vulnerability, system administrators are advised to update their PGP installation or use a different randomness source for key generation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Pretty Good Privacy

Affected Vendors

  • Broadcom