CVE-2002-0788
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users…
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-459
- Affected
- pgp/corporate desktop · pgp/freeware · pgp/personal security
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0052.htmlBroken Link, Patch, Vendor Advisory
- http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txtThird Party Advisory
- http://www.iss.net/security_center/static/9044.phpBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/4363Broken Link
- http://www.securityfocus.com/bid/4702Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0052.htmlBroken Link, Patch, Vendor Advisory
- http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/ReadMe.txtThird Party Advisory
- http://www.iss.net/security_center/static/9044.phpBroken Link, Patch, Vendor Advisory
- http://www.osvdb.org/4363Broken Link
- http://www.securityfocus.com/bid/4702Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.