CVE-2002-1696: Medium severity pgp pgp vulnerability
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1696?
CVE-2002-1696 is considered a moderate-severity vulnerability due to its potential for disclosing sensitive information.
How do I fix CVE-2002-1696?
To fix CVE-2002-1696, disable the 'Automatically decrypt/verify when opening messages' option in the PGP settings.
Which versions are affected by CVE-2002-1696?
CVE-2002-1696 affects PGP versions 7.0, 7.0.3, 7.0.4, and Microsoft Outlook 98 when certain settings are configured.
What data is exposed due to CVE-2002-1696?
CVE-2002-1696 can lead to the unintended saving of decrypted messages on the hard disk.
Is there a workaround for CVE-2002-1696?
A workaround for CVE-2002-1696 is to ensure the 'Always use Secure Viewer when decrypting' option is enabled.