CVE-2007-0603
Summary
| CVE | CVE-2007-0603 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-30 18:28:00 UTC |
| Updated | 2018-10-16 16:33:00 UTC |
| Description | PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pgp | Corporate Desktop | 9.5 | All | All | All |
| Application | Pgp | Corporate Desktop | 9.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PGP Desktop Windows Service Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| 32969 | OSVDB | osvdb.org | |
| Advisories - Research - Next Generation Security Software | MISC | www.ngssoftware.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| 20070125 Medium Risk Vulnerability in PGP Desktop | VULNWATCH | archives.neohapsis.com | |
| Medium Risk Vulnerability in PGP Desktop - CXSecurity.com | SREASON | securityreason.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| PGP Desktop Service Code Execution Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - PGP Desktop Input Validation Flaw in PGPServ.exe/PGPsdkServ.exe Services Lets Local Users Gain LocalSystem Privileges | SECTRACK | securitytracker.com | |
| US-CERT Vulnerability Note VU#102465 | CERT-VN | www.kb.cert.org | US Government Resource |
| 32970 | OSVDB | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.