Vulnerability Description
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgp | Pgp | 5.0_linux |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html
- http://www.cert.org/advisories/CA-2000-09.htmlUS Government Resource
- http://www.osvdb.org/1355
- http://www.securityfocus.com/bid/1251
- http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html
- http://www.cert.org/advisories/CA-2000-09.htmlUS Government Resource
- http://www.osvdb.org/1355
- http://www.securityfocus.com/bid/1251
FAQ
What is CVE-2000-0445?
CVE-2000-0445 is a vulnerability with a CVSS score of 2.1 (LOW). The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.
How severe is CVE-2000-0445?
CVE-2000-0445 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0445?
Check the references section above for vendor advisories and patch information. Affected products include: Pgp Pgp.