CVE-2002-2069
Summary
| CVE | CVE-2002-2069 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-12-31 05:00:00 UTC |
| Updated | 2008-09-05 20:32:00 UTC |
| Description | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pgp | Pgp | 6.5.1 | All | All | All |
| Application | Pgp | Pgp | 6.5.1i | All | All | All |
| Application | Pgp | Pgp | 6.5.2a | All | All | All |
| Application | Pgp | Pgp | 6.5.3 | All | All | All |
| Application | Pgp | Pgp | 6.5.8 | All | All | All |
| Application | Pgp | Pgp | 7.0 | All | All | All |
| Application | Pgp | Pgp | 7.0.3 | All | All | All |
| Application | Pgp | Pgp | 6.5.1 | All | All | All |
| Application | Pgp | Pgp | 6.5.1i | All | All | All |
| Application | Pgp | Pgp | 6.5.2a | All | All | All |
| Application | Pgp | Pgp | 6.5.3 | All | All | All |
| Application | Pgp | Pgp | 6.5.8 | All | All | All |
| Application | Pgp | Pgp | 7.0 | All | All | All |
| Application | Pgp | Pgp | 7.0.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Multiple Vendor NTFS File Wipe Vulnerability | BID | www.securityfocus.com | |
| M-034: Window File Wiping Utilities Miss Alternate Data Streams | CIAC | www.ciac.org | Vendor Advisory |
| ISS X-Force Database: ntfs-ads-file-wipe (7953): NTFS file-wiping utilities do not properly clean data in Alternate Data Streams | XF | www.iss.net | |
| Kurt Seifried - Security / Security Advisories / KSSA-003 NTFS Alternate data streams | MISC | www.seifried.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.