Back

CVE-2001-1016

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

Published: Sep 4, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (8)

Vendor Product Version
pgp corporate_desktop 7.1
pgp e-business_server 6.5.8
pgp e-business_server 7.0.4
pgp e-business_server 7.1
pgp freeware 7.0.3
pgp personal_security 7.0.3
pgp pgp 5.0
pgp pgp 6.0.2

GitHub Security Advisory GHSA-cg3c-pj78-hrh5

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.36%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub