Vulnerability Description
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgp | Personal Privacy | 7.0 |
| Microsoft | Outlook | 98 |
Related Weaknesses (CWE)
References
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&Broken Link
- http://www.securityfocus.com/bid/3825Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7900Third Party AdvisoryVDB Entry
- http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&Broken Link
- http://www.securityfocus.com/bid/3825Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7900Third Party AdvisoryVDB Entry
FAQ
What is CVE-2002-1696?
CVE-2002-1696 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Alwa...
How severe is CVE-2002-1696?
CVE-2002-1696 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1696?
Check the references section above for vendor advisories and patch information. Affected products include: Pgp Personal Privacy, Microsoft Outlook.