First published: Mon Aug 12 2002(Updated: )
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PGP (Pretty Good Privacy) | =7.0.3 | |
PGP Corporate Desktop | =7.1 | |
PGP (Pretty Good Privacy) | =7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0788 is considered a medium severity vulnerability due to its potential for local exploitation.
To mitigate CVE-2002-0788, users should upgrade to a newer version of PGP that does not exhibit this vulnerability.
CVE-2002-0788 affects users of PGP versions 7.0.3 and 7.1 on Windows operating systems.
Exploiting CVE-2002-0788 could allow local users or attackers with physical access to retrieve sensitive information from cleartext temporary files.
CVE-2002-0788 arises from a flaw in how certain PGP versions handle temporary files in conjunction with the Windows Encrypted File System.