PT-2000-1611 · Pgp · Pgp

Publicado

2000-10-20

·

Atualizado

2008-09-10

·

CVE-2000-0678

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PGP versions 5.5.x through 6.5.3
Description The issue arises from improper checking of an Additional Decryption Key (ADK) in the signed portion of a public certificate. This allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
Recommendations For versions 5.5.x through 6.5.3, consider restricting access to certificate modification to prevent exploitation until a proper fix is applied. As a temporary workaround, carefully monitor and control any changes made to public certificates to minimize the risk of decryption by unauthorized parties.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0678

Produtos afetados

Pgp