PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3961 | vdb entry third party advisory broken link |
http://online.securityfocus.com/archive/1/252407 | mailing list vendor advisory vdb entry third party advisory broken link |
http://www.iss.net/security_center/static/8008.php | vdb entry broken link vendor advisory |