First published: Fri Oct 13 2000(Updated: )
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pgp Pgp | =6.5.1i | |
Pgp Pgp | =5.5.3i | |
Pgp Pgp | =6.5.3i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.