Vulnerability Name:

CVE-2002-1696 (CCN-7900)

Assigned:2002-01-08
Published:2002-01-08
Updated:2017-07-11
Summary:Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Configuration
References:Source: MITRE
Type: CNA
CVE-2002-1696

Source: CCN
Type: Windows NTBugTraq Mailing List, Tue, 8 Jan 2002 18:33:03 -0500
PGP 7.0 Outlook Plug-in flaw

Source: NTBUGTRAQ
Type: UNKNOWN
20020108 PGP 7.0 Outlook Plug-in flaw

Source: CCN
Type: OSVDB ID: 11959
PGP Outlook Plug-in Decrypted E-mail Persistence

Source: CCN
Type: Network Associates Web site
PGP Security Product Patches and Hotfixes

Source: BID
Type: UNKNOWN
3825

Source: CCN
Type: BID-3825
PGP Outlook Plug-In Insecure Message Storage Vulnerability

Source: XF
Type: UNKNOWN
pgp-outlook-decrypted-copy(7900)

Source: XF
Type: UNKNOWN
pgp-outlook-decrypted-copy(7900)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:outlook:98:*:*:*:*:*:*:*
  • OR cpe:/a:pgp:pgp:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:pgp:pgp:7.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:pgp:pgp:7.0.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:outlook:98:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft outlook 98
    pgp pgp 7.0
    pgp pgp 7.0.3
    pgp pgp 7.0.4
    microsoft outlook 98