CVE Vulnerabilities

CVE-2002-0788

Incomplete Cleanup

Published: Aug 12, 2002 | Modified: Feb 08, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An interaction between PGP 7.0.3 with the wipe deleted files option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Corporate_desktop Pgp 7.1 (including) 7.1 (including)
Freeware Pgp 7.0.3 (including) 7.0.3 (including)
Personal_security Pgp 7.0.3 (including) 7.0.3 (including)

Potential Mitigations

References