Vulnerabilities > CVE-2008-5731 - Resource Management Errors vulnerability in PGP Desktop 9.0.6/9.9.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and possibly gain privileges via a certain METHOD_BUFFERED IOCTL request that overwrites portions of memory, related to a "Driver Collapse." NOTE: some of these details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | PGP Desktop 9.0.6 (PGPwded.sys) Local Denial of Service Exploit. CVE-2008-5731. Dos exploit for windows platform |
file | exploits/windows/dos/7556.php |
id | EDB-ID:7556 |
last seen | 2016-02-01 |
modified | 2008-12-23 |
platform | windows |
port | |
published | 2008-12-23 |
reporter | Evilcry |
source | https://www.exploit-db.com/download/7556/ |
title | PGP Desktop 9.0.6 PGPwded.sys Local Denial of Service Exploit |
type | dos |
Nessus
NASL family | Windows |
NASL id | PGP_DESKTOP_9_10.NASL |
description | The version of PGP Desktop installed on the remote system is older than 9.10. As such, it reportedly is affected by the following issues : - The IOCTL handler in |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 36162 |
published | 2009-04-15 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/36162 |
title | PGP Desktop < 9.10 Multiple Local DoS |
code |
|
References
- http://osvdb.org/50914
- http://secunia.com/advisories/33310
- http://securityreason.com/securityalert/4811
- http://www.evilfingers.com/advisory/PGPDesktop_9_0_6_Denial_Of_Service.php
- http://www.evilfingers.com/advisory/PGPDesktop_9_0_6_Denial_Of_Service_POC.php
- http://www.securityfocus.com/archive/1/499572/100/0/threaded
- http://www.securityfocus.com/bid/32991
- http://www.securitytracker.com/id?1021493
- https://www.exploit-db.com/exploits/7556