CVE-2002-0788

An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2002-05/0052.html Broken Link Patch Vendor Advisory
http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txt Third Party Advisory
http://www.iss.net/security_center/static/9044.php Broken Link Patch Vendor Advisory
http://www.osvdb.org/4363 Broken Link
http://www.securityfocus.com/bid/4702 Broken Link Patch Third Party Advisory VDB Entry Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pgp:corporate_desktop:7.1:*:*:*:*:*:*:*
cpe:2.3:a:pgp:freeware:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:pgp:personal_security:7.0.3:*:*:*:*:*:*:*

History

08 Feb 2024, 20:13

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2002-05/0052.html - Patch, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2002-05/0052.html - Broken Link, Patch, Vendor Advisory
References () http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txt - () http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txt - Third Party Advisory
References () http://www.iss.net/security_center/static/9044.php - Patch, Vendor Advisory () http://www.iss.net/security_center/static/9044.php - Broken Link, Patch, Vendor Advisory
References () http://www.osvdb.org/4363 - () http://www.osvdb.org/4363 - Broken Link
References () http://www.securityfocus.com/bid/4702 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/4702 - Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
CWE NVD-CWE-Other CWE-459
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5

Information

Published : 2002-08-12 04:00

Updated : 2024-02-08 20:13


NVD link : CVE-2002-0788

Mitre link : CVE-2002-0788

CVE.ORG link : CVE-2002-0788


JSON object : View

Products Affected

pgp

  • personal_security
  • freeware
  • corporate_desktop
CWE
CWE-459

Incomplete Cleanup