PT-2001-1650 · Pgp · Pgp
Publicado
2001-05-24
·
Atualizado
2016-10-18
·
CVE-2001-0435
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PGP version 7.0
Description
The issue concerns the split key mechanism in PGP, which allows a key share holder to gain access to the entire key. This can be achieved by setting the
Cache passphrase while logged on option and capturing the passphrases of other share holders as they authenticate.Recommendations
For PGP version 7.0, consider disabling the
Cache passphrase while logged on option to prevent potential exploitation. Additionally, restrict access to the key sharing mechanism to minimize the risk of unauthorized access.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pgp