First published: Tue Dec 31 2002(Updated: )
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PGP (Pretty Good Privacy) | >=6.0.2<=6.5.8 | |
PGP (Pretty Good Privacy) | >=7.0<=7.1.1 | |
PGP OpenPGP | =6.5.1 | |
PGP OpenPGP | =6.5.1i | |
PGP OpenPGP | =6.5.2a | |
PGP OpenPGP | =6.5.3 | |
PGP OpenPGP | =6.5.8 | |
PGP OpenPGP | =7.0 | |
PGP OpenPGP | =7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2069 is considered a moderate severity vulnerability that could lead to sensitive data recovery.
To fix CVE-2002-2069, upgrade to a newer version of PGP that does not have this vulnerability.
CVE-2002-2069 affects PGP versions 6.x and 7.x, including specific versions like 6.5.1, 6.5.2a, 7.0, and 7.0.3.
The implications of CVE-2002-2069 include the potential exposure of sensitive information due to incomplete deletion processes.
To effectively mitigate CVE-2002-2069, it is recommended to upgrade, as there are no adequate workarounds for this vulnerability.