Vulnerability Description
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pgp | Pgp | 7.0.4 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0313.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0322.html
- http://www.iss.net/security_center/static/9690.phpPatch
- http://www.securityfocus.com/bid/5318
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0313.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0322.html
- http://www.iss.net/security_center/static/9690.phpPatch
- http://www.securityfocus.com/bid/5318
FAQ
What is CVE-2002-1977?
CVE-2002-1977 is a vulnerability with a CVSS score of 2.1 (LOW). Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
How severe is CVE-2002-1977?
CVE-2002-1977 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1977?
Check the references section above for vendor advisories and patch information. Affected products include: Pgp Pgp.