CA-2000-18.PGP...

- AV AC AU C I A
发布: 2000-08-25
修订: 2025-04-13

There is a serious problem in the handling of certificates when encrypting with PGP versions 5.5.x through 6.5.3. The vulnerability lies within PGP's handling of Additional Decryption Keys (ADK) allowing a malicious user to insert an additional public key into the unsigned part of the user's public key-certificate. The malicious user may then be able to recover the plaintext of any encrypted text sent to the victim using the altered certificate.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息