Remote PGP Outlook Encryption Plug-in Vulnerability
A vulnerability exists in NAI’s PGP Outlook Encryption plug-in that can result in remote compromise of the vulnerable system.
July 14, 2002
Reported July 10, 2002, by eEyeDigital Security.
VERSIONS AFFECTED
· Network Associates (NAI) Pretty Good Privacy (PGP)Desktop Security 7.0.4
· NAI PGP Personal Security 7.0.3
· NAI PGP Freeware 7.0.3
DESCRIPTION
Avulnerability exists in NAI’s PGP Outlook Encryption plug-in contained in theabove products that can result in remote compromise of the vulnerable system. Bysending a specially crafted email to a vulnerable system, an attacker canexecute code remotely on the vulnerable system. Read eEye Digital Security’s advisoryfor a detailed explanation of this vulnerability.
VENDOR RESPONSE
NAI has released a patchfor the latest version of the PGP Outlook plug-in to address this vulnerability.
CREDIT
Discoveredby Marc Maiffret and Riley Hassell of eEyeDigital Security.
About the Author
You May Also Like