LOW · 2.1

CVE-2002-1977

Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.

Vulnerability Description

Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PgpPgp7.0.4

References

FAQ

What is CVE-2002-1977?

CVE-2002-1977 is a vulnerability with a CVSS score of 2.1 (LOW). Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.

How severe is CVE-2002-1977?

CVE-2002-1977 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-1977?

Check the references section above for vendor advisories and patch information. Affected products include: Pgp Pgp.