VulnerabilityModified
CVE-2002-1977
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
LOW 2.1EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- pgp/pgp
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0313.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0322.html
- http://www.iss.net/security_center/static/9690.phpPatch
- http://www.securityfocus.com/bid/5318
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0313.html
- http://archives.neohapsis.com/archives/bugtraq/2002-07/0322.html
- http://www.iss.net/security_center/static/9690.phpPatch
- http://www.securityfocus.com/bid/5318
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.