|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
PGP contains a flaw that allows a remote attacker to potentially execute arbitrary code. The issue is due to the ASCII armor parser exctracting binary files which may contain .DLL files, which Windows operating systems can be tricked into executing. If an attacker sends a specially crafted armored attachment, this would allow them to execute arbitrary code or commands via the malicious DLL.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Technical |
This vulnerability affects PGP on the following platforms: Windows 95, 98, Millennium, NT, Windows 2000
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, PGP Corporation has released a patch to address this vulnerability.
|
|
Products |
|
PGP
 |
5.x |
6.x |
7.0 |
7.0.3 |
|
|
|
|
Credit |
- Chris Anley - chris
ngssoftware.com - Next Generation Security Software
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|