Vulnerabilities > CVE-2002-0788 - Incomplete Cleanup vulnerability in PGP Corporate Desktop, Freeware and Personal Security

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
pgp
CWE-459

Summary

An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

Vulnerable Configurations

Part Description Count
Application
Pgp
3

Common Weakness Enumeration (CWE)