VulnerabilityModified
CVE-2005-4151
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.
LOW 2.1EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Affected
- pgp/desktop
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/pgp_slackspace/Exploit
- http://secunia.com/advisories/17827Vendor Advisory
- http://www.osvdb.org/21569
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/archive/1/419282/100/0/threaded
- http://www.securityfocus.com/archive/1/419654/100/0/threaded
- http://www.securityfocus.com/bid/15784Exploit
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0349.html
- http://metasploit.com/research/vulns/pgp_slackspace/Exploit
- http://secunia.com/advisories/17827Vendor Advisory
- http://www.osvdb.org/21569
- http://www.securityfocus.com/archive/1/419077/100/0/threaded
- http://www.securityfocus.com/archive/1/419282/100/0/threaded
- http://www.securityfocus.com/archive/1/419654/100/0/threaded
- http://www.securityfocus.com/bid/15784Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.