vendor:
PGP Desktop
by:
Unknown
7.5
CVSS
HIGH
Arbitrary File Creation
CWE
Product Name: PGP Desktop
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-Unknown
CPE: a:pgp_corp:pgp_desktop
Platforms Tested:
Unknown
Arbitrary File Creation in PGP ASCII Armor Decoder
The flaw in the implementation of the PGP ASCII Armor decoder allows an attacker to create an arbitrary file on a user's system. This can be exploited by decoding a specially crafted .sig file that contains malicious instructions to create the desired file. The attacker can choose the location and content of the file.
Mitigation:
To mitigate this vulnerability, it is recommended to update the PGP software to the latest version. Additionally, users should exercise caution when opening and verifying files using PGP, especially if they originate from untrusted sources.