Vulnerability Note VU#102465
PGP Desktop service fails to validate user supplied data
Overview
PGP Desktop fails to properly validate objects passed into the PGP Desktop service. This vulnerability may allow a remote, authenticated attacker to execute arbitrary code.
Description
PGP Desktop versions prior to 9.5.1 fail to properly validate objects passed into the PGP Desktop service (PGPServ.exe/PGPsdkServ.exe). This service is installed by PGP Desktop to transport objects and data between the PGP clients and the PGP Desktop service. The PGP Desktop service fails to properly validate user-supplied data. This may allow a remote, authenticated attacker to overwrite arbitrary memory. |
Impact
A remote, authenticated attacker may be able to execute arbitrary code, possibly with elevated privileges. |
Solution
Upgrade PGP has addressed this issue in PGP version 9.5.1 and above. |
Workarounds
2. Use a third-party Personal Firewall, or the built-in Windows XP SP2 Firewall. Block foreign connections to your RPC/Filesharing services. |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| PGP Corporation | Vulnerable | - | 12 Feb 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=703
- http://secunia.com/advisories/23938/
- http://www.ngssoftware.com/advisories/medium-risk-vulnerability-in-pgp-desktop/
- http://www.itnews.com.au/newsstory.aspx?CIaNID=44982&src=site-marq
- http://www.vnunet.com/vnunet/news/2173564/flaw-found-pgp-encryption
Credit
This vulnerability was reported by Peter Winter-Smith of NGSSoftware.
This document was written by Katie Steiner.
Other Information
- CVE IDs: CVE-2007-0603
- Date Public: 25 Jan 2007
- Date First Published: 31 Jan 2007
- Date Last Updated: 12 Feb 2007
- Severity Metric: 4.04
- Document Revision: 23
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify