First published: Tue Sep 04 2001(Updated: )
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pgp Freeware | =7.0.3 | |
Pgp E-business Server | =6.5.8 | |
PGP Corporate Desktop | =7.1 | |
Pgp Pgp | =6.0.2 | |
Pgp Pgp | =5.0 | |
Pgp Personal Security | =7.0.3 | |
Pgp E-business Server | =7.1 | |
Pgp E-business Server | =7.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.