AplusWebMaster
Topic Starter
FYI…
- http://www.us-cert.gov/current/#pgp0valdt
January 31, 2007 ~ "US-CERT is aware of a memory corruption vulnerability in the PGP Desktop service. The PGP Desktop service fails to validate user-supplied data. By sending a specially crafted object to the PGP Desktop service, a remote, authenticated attacker may be able to execute arbitrary code with potentially elevated privileges on a vulnerable system. More information about this vulnerability is located in the following:
Vulnerability Note VU#102465… http://www.kb.cert.org/vuls/id/102465
PGP states that upgrading to the latest version* of PGP Desktop will address this vulnerability.
> https://pgp.custhelp.com/cgi-bin/pgp.cfg/ph…php?p_faqid=703
Last Updated: 01/31/2007 02:51 PM ~ "…This situation affects versions of PGP Desktop earlier than version 9.5.1, it does not affect any subsequent version of the product…"
* http://www.pgp.com/products/index.html
- http://secunia.com/advisories/23938/
.
- http://www.us-cert.gov/current/#pgp0valdt
January 31, 2007 ~ "US-CERT is aware of a memory corruption vulnerability in the PGP Desktop service. The PGP Desktop service fails to validate user-supplied data. By sending a specially crafted object to the PGP Desktop service, a remote, authenticated attacker may be able to execute arbitrary code with potentially elevated privileges on a vulnerable system. More information about this vulnerability is located in the following:
Vulnerability Note VU#102465… http://www.kb.cert.org/vuls/id/102465
PGP states that upgrading to the latest version* of PGP Desktop will address this vulnerability.
> https://pgp.custhelp.com/cgi-bin/pgp.cfg/ph…php?p_faqid=703
Last Updated: 01/31/2007 02:51 PM ~ "…This situation affects versions of PGP Desktop earlier than version 9.5.1, it does not affect any subsequent version of the product…"
* http://www.pgp.com/products/index.html
- http://secunia.com/advisories/23938/
.