Total vulnerabilities in the database
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which has already been signed by the third party, aka the "PGPsdk Key Validity Vulnerability."
Software | From | Fixed in |
---|---|---|
pgp / freeware | 7.0.3 | 7.0.3.x |
pgp / e-business_server | 6.5.8 | 6.5.8.x |
pgp / corporate_desktop | 7.1 | 7.1.x |
pgp / pgp | 6.0.2 | 6.0.2.x |
pgp / pgp | 5.0 | 5.0.x |
pgp / personal_security | 7.0.3 | 7.0.3.x |
pgp / e-business_server | 7.1 | 7.1.x |
pgp / e-business_server | 7.0.4 | 7.0.4.x |