CVE Vulnerabilities

CVE-2000-0678

Published: Oct 20, 2000 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victims public certificate to decrypt any data that has been encrypted with the modified certificate.

Affected Software

Name Vendor Start Version End Version
Pgp Pgp 6.5.1i 6.5.1i
Pgp Pgp 5.5.3i 5.5.3i
Pgp Pgp 6.5.3i 6.5.3i

References