First published: Fri Oct 13 2000(Updated: )
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PGP OpenPGP | =6.5.1i | |
PGP OpenPGP | =5.5.3i | |
PGP OpenPGP | =6.5.3i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2000-0678 is considered high due to the potential for data decryption without authorization.
To fix CVE-2000-0678, update to a version of PGP that does not contain this vulnerability.
CVE-2000-0678 allows an attacker to decrypt sensitive data by manipulating a victim's public certificate.
CVE-2000-0678 affects PGP versions 5.5.x through 6.5.3.
An attacker with the ability to modify a user's public certificate can exploit CVE-2000-0678.