CVE-2002-0685
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via a large, malformed mail message.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- pgp/desktop security · pgp/freeware · pgp/personal security
- Source
- cve@mitre.org
References
- http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.04/hotfix/ReadMe.txtPatch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=102634756815773&w=2
- http://marc.info/?l=ntbugtraq&m=102639521518942&w=2
- http://www.iss.net/security_center/static/9525.php
- http://www.kb.cert.org/vuls/id/821139US Government Resource
- http://www.osvdb.org/4364
- http://www.securityfocus.com/bid/5202
- http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.04/hotfix/ReadMe.txtPatch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=102634756815773&w=2
- http://marc.info/?l=ntbugtraq&m=102639521518942&w=2
- http://www.iss.net/security_center/static/9525.php
- http://www.kb.cert.org/vuls/id/821139US Government Resource
- http://www.osvdb.org/4364
- http://www.securityfocus.com/bid/5202
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.