CVE-2000-0678 — PGP vulnerability
2 documents2 sources
Severity
5.0MEDIUMNVD
EPSS
0.4%
top 36.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
1
Timeline
PublishedOct 20
Latest updateApr 30
Description
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9