PGP Outlook Plug-In Insecure Message Storage Vulnerability
BID:3825
Info
PGP Outlook Plug-In Insecure Message Storage Vulnerability
| Bugtraq ID: | 3825 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 08 2002 12:00AM |
| Updated: | Jan 08 2002 12:00AM |
| Credit: | This vulnerability was submitted to the NTBugtraq mailing list on January 8th, 2002 by Mark Wiater <[email protected]>. |
| Vulnerable: |
Network Associates PGP 7.0.4 Network Associates PGP 7.0.3 Network Associates PGP 7.0 |
| Not Vulnerable: |
Network Associates PGP 7.1.1 |
Discussion
PGP Outlook Plug-In Insecure Message Storage Vulnerability
PGP Security provides privacy and data confidentiality software. The Outlook Plug-in allows users to send and receive encrypted mail via Microsoft Outlook mail clients.
A problem has been discovered in PGP Outlook Plug-in which may create a false sense of security for users of this product.
When a user replies to an encrypted message, a decrypted copy of the message is saved silently to disk on the system. The user receives no notification of this event.
This issue only occurs when the user replies to a message and the "Automatically decrypt/verify when opening messages" option is checked, and "Always use Secure Viewer when decrypting" option is not checked.
PGP Security provides privacy and data confidentiality software. The Outlook Plug-in allows users to send and receive encrypted mail via Microsoft Outlook mail clients.
A problem has been discovered in PGP Outlook Plug-in which may create a false sense of security for users of this product.
When a user replies to an encrypted message, a decrypted copy of the message is saved silently to disk on the system. The user receives no notification of this event.
This issue only occurs when the user replies to a message and the "Automatically decrypt/verify when opening messages" option is checked, and "Always use Secure Viewer when decrypting" option is not checked.
Exploit / POC
PGP Outlook Plug-In Insecure Message Storage Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PGP Outlook Plug-In Insecure Message Storage Vulnerability
Solution:
This issue has been addressed by the vendor in version 7.1.1.
Solution:
This issue has been addressed by the vendor in version 7.1.1.
References
PGP Outlook Plug-In Insecure Message Storage Vulnerability
References:
References:
- PGP 7.0 Outlook Plug-in flaw (NTBugtraq)