Vulnerability Details CVE-2001-1016
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2001-1016
-
cpe:2.3:a:pgp:corporate_desktop:7.1
-
cpe:2.3:a:pgp:e-business_server:6.5.8
-
cpe:2.3:a:pgp:e-business_server:7.0.4
-
cpe:2.3:a:pgp:e-business_server:7.1
-
cpe:2.3:a:pgp:freeware:7.0.3
-
cpe:2.3:a:pgp:personal_security:7.0.3
-
-