|
 |
|
PGP Desktop Wipe Free Space Security Issue
|
|
|
|
|
Secunia Advisory:
|
SA17827
|
|
|
Release Date:
|
2005-12-09
|
|
Last Update:
|
2005-12-27
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
Exposure of sensitive information
|
|
Where:
|
Local system
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | PGP Corporate Desktop 8.x PGP Corporate Desktop 9.x
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Vinnie Liu has reported a security issue in PGP Desktop, which can be exploited by malicious people to disclose potentially sensitive information.
The security issue is caused due to data contained within the slack space of files on a NTFS drive not being correctly wiped when the Wipe Free Space tool is used. This can potentially be exploited to disclose the contents of any information that is contained within the slack space.
The security issue has been reported in the following versions.
* PGP Desktop Professional 9.0.3 Build 2932.
* PGP Desktop 8.x
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution: Update to PGP Desktop Professional version 9.0.4 Build 4034 or later.
Provided and/or discovered by: Vinnie Liu
Changelog: 2005-12-27: Updated "Solution Status" and "Solution" sections.
Original Advisory: http://metasploit.com/research/vulns/pgp_slackspace/
http://metasploit.com/projects/antiforensics/BH2005-Catch_Me_If_You_Can.ppt
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
1 Related Secunia Security Advisories
|
|
|
1. PGP Desktop Service Code Execution Vulnerability
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|