PT-2001-1650 · Pgp · Pgp

Publicado

2001-05-24

·

Atualizado

2016-10-18

·

CVE-2001-0435

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PGP version 7.0
Description The issue concerns the split key mechanism in PGP, which allows a key share holder to gain access to the entire key. This can be achieved by setting the Cache passphrase while logged on option and capturing the passphrases of other share holders as they authenticate.
Recommendations For PGP version 7.0, consider disabling the Cache passphrase while logged on option to prevent potential exploitation. Additionally, restrict access to the key sharing mechanism to minimize the risk of unauthorized access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0435

Produtos afetados

Pgp