Back

CVE-2003-0978

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.

Published: Jan 5, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
gnu privacy_guard 1.2
gnu privacy_guard 1.2.1
gnu privacy_guard 1.2.2
gnu privacy_guard 1.2.2
gnu privacy_guard 1.2.3
gnu privacy_guard 1.3.3

GitHub Security Advisory GHSA-chjf-v68x-qx8j

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg)...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.76%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub