Lucene search

K
nvd[email protected]NVD:CVE-2008-5731
HistoryDec 26, 2008 - 5:30 p.m.

CVE-2008-5731

2008-12-2617:30:00
CWE-399
web.nvd.nist.gov
2

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.7%

The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and possibly gain privileges via a certain METHOD_BUFFERED IOCTL request that overwrites portions of memory, related to a “Driver Collapse.” NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
pgpdesktopMatch9.0.6
OR
pgpdesktopMatch9.9.0
VendorProductVersionCPE
pgpdesktop9.0.6cpe:2.3:a:pgp:desktop:9.0.6:*:*:*:*:*:*:*
pgpdesktop9.9.0cpe:2.3:a:pgp:desktop:9.9.0:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.7%

Related for NVD:CVE-2008-5731