CVE Vulnerabilities

CVE-2002-0788

Incomplete Cleanup

Published: Aug 12, 2002 | Modified: Nov 20, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An interaction between PGP 7.0.3 with the wipe deleted files option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

Weakness 

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software 

Name Vendor Start Version End Version
Corporate_desktop Pgp 7.1 (including) 7.1 (including)
Freeware Pgp 7.0.3 (including) 7.0.3 (including)
Personal_security Pgp 7.0.3 (including) 7.0.3 (including)

Potential Mitigations 

References