xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

PGP 非法Key显示漏洞


发布时间:2001-09-07
更新时间:2001-09-07
严重程度:
威胁程度:欺骗
错误类型:设计错误
利用方式:服务器模式

受影响系统
Network Associates PGP 6.0.2
   - Microsoft Windows 98
   - Microsoft Windows 95
   - Microsoft Windows NT 4.0
Network Associates PGP 5.0
   - Microsoft Windows 98
   - Microsoft Windows 95
   - Microsoft Windows NT 4.0
Network Associates PGP Corporate Desktop 7.1
   - Microsoft Windows ME
   - Microsoft Windows 98se
   - Microsoft Windows 98
   - Microsoft Windows 95b
   - Microsoft Windows 95OSR2
   - Microsoft Windows NT 4.0SP6a
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP5
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP4
      + Microsoft Windows NT 4.0
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - Apple MacOS 9.0
Network Associates PGP E-Business Server 7.1
   - Sun Solaris 8.0
   - Sun Solaris 7.0
   - Sun Solaris 2.6
   - Sun Solaris 2.5.1
   - RedHat Linux 7.2
   - RedHat Linux 7.1 i386
   - RedHat Linux 7.0J i386
   - RedHat Linux 7.0 i386
   - RedHat Linux 6.2E i386
   - RedHat Linux 6.2 i386
   - RedHat Linux 6.1 i386
   - RedHat Linux 6.0 i386
   - RedHat Linux 5.x
   - Microsoft Windows NT 4.0SP6a
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP5
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP4
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP3
      + Microsoft Windows NT 4.0
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - IBM OS/390 V2R9
   - IBM OS/390 V2R6
   - IBM AIX 5.1
   - IBM AIX 4.3.3
   - IBM AIX 4.3.2
   - IBM AIX 4.3.1
   - IBM AIX 4.3
   - IBM AIX 4.2.1
   - IBM AIX 4.2
   - HP HP-UX 11.4
   - HP HP-UX 11.11
   - HP HP-UX 11.0
   - HP HP-UX 10.9
   - HP HP-UX 10.8
   - HP HP-UX 10.34
   - HP HP-UX 10.30
   - HP HP-UX 10.26
   - HP HP-UX 10.20
Network Associates PGP E-Business Server 7.0.4
   - Sun Solaris 8.0
   - Sun Solaris 7.0
   - Sun Solaris 2.6
   - Sun Solaris 2.5.1
   - RedHat Linux 7.2
   - RedHat Linux 7.1 i386
   - RedHat Linux 7.0J i386
   - RedHat Linux 7.0 i386
   - RedHat Linux 6.2E i386
   - RedHat Linux 6.2 i386
   - RedHat Linux 6.1 i386
   - RedHat Linux 6.0 i386
   - RedHat Linux 5.x
   - Microsoft Windows NT 4.0SP6a
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP5
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP4
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP3
      + Microsoft Windows NT 4.0
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - IBM OS/390 V2R9
   - IBM OS/390 V2R6
   - IBM AIX 5.1
   - IBM AIX 4.3.3
   - IBM AIX 4.3.2
   - IBM AIX 4.3.1
   - IBM AIX 4.3
   - IBM AIX 4.2.1
   - IBM AIX 4.2
Network Associates PGP E-Business Server 6.5.8
   - IBM OS/390 V2R9
   - IBM OS/390 V2R6
Network Associates PGP Freeware 7.0.3
   - Microsoft Windows ME
   - Microsoft Windows 98se
   - Microsoft Windows 98
   - Microsoft Windows 95b
   - Microsoft Windows 95OSR2
   - Microsoft Windows NT 4.0SP6a
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP5
      + Microsoft Windows NT 4.0
   - Microsoft Windows NT 4.0SP4
      + Microsoft Windows NT 4.0
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - Apple MacOS 9.0
Network Associates PGP Personal Security 7.0.3
   - Microsoft Windows ME
   - Microsoft Windows 98se
   - Microsoft Windows 98
   - Microsoft Windows 95
   - Microsoft Windows 2000 SP2
      + Microsoft Windows 2000
   - Microsoft Windows 2000 SP1
      + Microsoft Windows 2000
   - Microsoft Windows 2000
   - Apple MacOS 9.0
详细描述
PGP是提供数据加密和安全的软件,其中,其中PGP显示KEY有效性里存在安全漏洞可以导致用户通过被欺骗接受使用非法用户ID关联的KEY。

如果这个KEY被接受攻击者就可以伪造签名。

测试代码
尚无

解决方案
请下载补丁程序:

Network Associates PGP Corporate Desktop 7.1:

Network Associates hotfix PGP_Hotfix0904_Win32.zip
http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/PGP_Hotfix0904_Win32.zip
Hotfix for Windows platforms.

Network Associates hotfix PGP_Hotfix0904_Mac.sit.bin
http://download.nai.com/products/licensed/pgp/desktop_security/mac/version_7.1/hotfix/PGP_Hotfix0904_Mac.sit.bin
Hotfix for Mac platform.

Network Associates PGP E-Business Server 7.1:

Network Associates hotfix PGPEBiz71_Hotfix0904_Linux.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.1/hotfix/PGPEBiz71_Hotfix0904_Linux.tar.gz
Hotfix for Linux.

Network Associates hotfix PGPEBiz71_Hotfix0904_Solaris.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.1/hotfix/PGPEBiz71_Hotfix0904_Solaris.tar.gz
Hotfix for Solaris.

Network Associates hotfix PGPEBiz71_Hotfix0904_AIX.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.1/hotfix/PGPEBiz71_Hotfix0904_AIX.tar.gz
Hotfix for AIX.

Network Associates hotfix PGPEBiz71_Hotfix0904_HPUX.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.1/hotfix/PGPEBiz71_Hotfix0904_HPUX.tar.gz
Hotfix for HPUX.

Network Associates PGP E-Business Server 7.0.4:

Network Associates hotfix PGPEBiz70_Hotfix0904_Linux.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.0/hotfix/PGPEBiz70_Hotfix0904_Linux.tar.gz
Hotfix for Linux.

Network Associates hotfix PGPEBiz70_Hotfix0904_Solaris.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.0/hotfix/PGPEBiz70_Hotfix0904_Solaris.tar.gz
Hotfix for Solaris.

Network Associates hotfix PGPEBiz70_Hotfix0904_AIX.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.0/hotfix/PGPEBiz70_Hotfix0904_AIX.tar.gz
Hotfix for AIX.

Network Associates hotfix PGPEBiz70_Hotfix0904_HPUX.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/unix/version_7.0/hotfix/PGPEBiz70_Hotfix0904_HPUX.tar.gz
Hotfix for HPUX.

Network Associates PGP E-Business Server 6.5.8:

Network Associates hotfix PGPEBus658_Hotfix0904_OS390.tar.gz
http://download.nai.com/products/licensed/pgp/e-business/MVS/version_6.5.8/hotfix/PGPEBus658_Hotfix0904_OS390.tar.gz
Hotfix for OS/390 Platform.

Network Associates PGP Freeware 7.0.3:

Network Associates hotfix PGP_Hotfix0904_Win32.zip
http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/PGP_Hotfix0904_Win32.zip
Hotfix for Windows platforms.

Network Associates hotfix PGP_Hotfix0904_Mac.sit.bin
http://download.nai.com/products/licensed/pgp/desktop_security/mac/version_7.1/hotfix/PGP_Hotfix0904_Mac.sit.bin
Hotfix for Mac platform.

Network Associates PGP Personal Security 7.0.3:

Network Associates hotfix PGP_Hotfix0904_Win32.zip
http://download.nai.com/products/licensed/pgp/desktop_security/windows/version_7.1/hotfix/PGP_Hotfix0904_Win32.zip
Hotfix for Windows platforms.

Network Associates hotfix PGP_Hotfix0904_Mac.sit.bin
http://download.nai.com/products/licensed/pgp/desktop_security/mac/version_7.1/hotfix/PGP_Hotfix0904_Mac.sit.bin
Hotfix for Mac platform.

相关信息