HIGH · 7.5

CVE-2001-1016

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, wh...

Vulnerability Description

PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PgpCorporate Desktop7.1
PgpE-Business Server6.5.8
PgpFreeware7.0.3
PgpPersonal Security7.0.3
PgpPgp5.0

References

FAQ

What is CVE-2001-1016?

CVE-2001-1016 is a vulnerability with a CVSS score of 7.5 (HIGH). PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, wh...

How severe is CVE-2001-1016?

CVE-2001-1016 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1016?

Check the references section above for vendor advisories and patch information. Affected products include: Pgp Corporate Desktop, Pgp E-Business Server, Pgp Freeware, Pgp Personal Security, Pgp Pgp.