PT-2007-2061 · Pgp · Pgp Desktop

Peter Winter-Smith

·

Published

2007-01-30

·

Updated

2018-10-16

·

CVE-2007-0603

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PGP Desktop versions prior to 9.5.1
Description The issue concerns the lack of validation for data objects received over specific named pipes, allowing remote authenticated users to gain privileges. This is achieved by sending a data object that represents an absolute pointer, leading to code execution at the corresponding address. The affected named pipes are related to PGPServ.exe and PGPsdkServ.exe.
Recommendations For versions prior to 9.5.1, update to version 9.5.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0603

Affected Products

Pgp Desktop