Remote PGP Outlook Encryption Plug-in Vulnerability

A vulnerability exists in NAI’s PGP Outlook Encryption plug-in that can result in remote compromise of the vulnerable system.

Ken Pfeil

July 14, 2002

1 Min Read
ITPro Today logo

Reported July 10, 2002, by eEyeDigital Security.

VERSIONS AFFECTED

 

·        Network Associates (NAI) Pretty Good Privacy (PGP)Desktop Security 7.0.4

·        NAI PGP Personal Security 7.0.3

·        NAI PGP Freeware 7.0.3

 

DESCRIPTION
Avulnerability exists in NAI’s PGP Outlook Encryption plug-in contained in theabove products that can result in remote compromise of the vulnerable system. Bysending a specially crafted email to a vulnerable system, an attacker canexecute code remotely on the vulnerable system. Read eEye Digital Security’s advisoryfor a detailed explanation of this vulnerability.

 

VENDOR RESPONSE

NAI has released a patchfor the latest version of the PGP Outlook plug-in to address this vulnerability.

 

CREDIT
Discoveredby Marc Maiffret and Riley Hassell of eEyeDigital Security.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like