CVE Vulnerabilities

CVE-2002-0788

Incomplete Cleanup

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An interaction between PGP 7.0.3 with the wipe deleted files option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
Corporate_desktopPgp7.1 (including)7.1 (including)
FreewarePgp7.0.3 (including)7.0.3 (including)
Personal_securityPgp7.0.3 (including)7.0.3 (including)

Potential Mitigations

References