CVE-2007-0603
Summary
| CVE | CVE-2007-0603 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-30 18:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address. |
Risk And Classification
Primary CVSS: v2.0 7.1 from [email protected]
AV:N/AC:H/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pgp | Corporate Desktop | 9.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/32970 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| PGP Desktop Service Code Execution Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PGP Desktop Windows Service Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories - Research - Next Generation Security Software | af854a3a-2127-422b-91ae-364da2661108 | www.ngssoftware.com | Vendor Advisory |
| SecurityTracker.com Archives - PGP Desktop Input Validation Flaw in PGPServ.exe/PGPsdkServ.exe Services Lets Local Users Gain LocalSystem Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| archives.neohapsis.com/archives/vulnwatch/2007-q1/0025.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#102465 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Medium Risk Vulnerability in PGP Desktop - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| osvdb.org/32969 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.