Next Page >>
PGP Desktop
=====================================================================
PGP Desktop version 9.10.x-10.0.0 Insecure DLL Hijacking
Vulnerability (tsp.dll, tvttsp.dll)
=====================================================================
1. OVERVIEW
The PGP Desktop application is vulnerable to Insecure DLL Hijacking
Vulnerability. Similar terms that describe this vulnerability
----------------------------------------------------------------------
(PT-2009-01) Positive Technologies Security Advisory
PGP Desktop Pgpdisk.sys And Pgpwded.sys Multiple Vulnerabilities
----------------------------------------------------------------------
---[ Affected Software ]
---------------------------------------------------
Advisory:
PGP Desktop 9.0.6 Denial Of Service Vulnerability.
Version Affected:
PGP Desktop 9.0.6 [Build 6060] (other version could be affected)
Component Affected:
PGPwded.sys
valid.
I made a PoC using inline assembly and C. But it doesn't open to the public
because of the vendor's request. (Just refer above descriptions.)
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.7.1 (Build 1503)
Charset: utf-8
wj8DBQFH+eM+zuoR/xLtCioRAhKKAJ4nkA8EGap6fZ+xvRJSNpCDlcanwQCglsYb
p8LCGeXrEnMoshPDBVB4dOc=
=OZDe
Copyright 2011 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFOxgCiDEcm8Vbi9kMRAvXfAKC3khDTnSPvVqMr/w2MnsMs+19upgCgyBHl
vO3aPCGs8oG9FalVVKGVE0Q=
=50f0
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2008 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFI0zaAS2KysvBH1xkRAmxoAJ9HOs6f0HR69u6aZ/DO3sTLIWDPXwCcDcM0
zFTK/nRyfvSJadlTBxu7NCI=
=deb5
Jeff Moss
Black Hat
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)
Charset: us-ascii
wsBVAwUBR174IkqsDNqTZ/G1AQiIUQf/XyglqmcmPmip3DFaPcCqALwSpAJthhdb
zic7LG8O4JiZGYAJ3nQFtbh6lS4HHsfwOIxd4lLX9k/LC9rOJ7UEkj8xuTQwajzs
gP07jZpk0XWs6p23Z5a7Ipdxz83J8dfNN/j0z9OsG0tbe3GiIvy0f89E5qtKSYTV
Director
Black Hat
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.7.0 (Build 1012)
Charset: us-ascii
wsBVAwUBR9saXUqsDNqTZ/G1AQjHRAf+Kzu1JM+3uJfDYb4lnTzog1lPcT9bmKhI
Odwbpae5ISCKoJq3LQ20COwPdnEappUSvZPwO8KCfAxtub6eeHDIsKc03AoordGb
T+4V3KFJ2Bp+/lKNySA5X3SX+87VpTgo9kycmHSW6XmsIj+q1UKdHAtxXDhKYOnS
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFLtPVKS2KysvBH1xkRAr7QAJ9fmOGXceihgXteCto/P0/N4FOYpQCeNU+6
9mPchO6g2qdEqzK4oDoGbl8=
=focv
Jeff Moss
Black Hat
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)
Charset: us-ascii
wsBVAwUBR2mn8kqsDNqTZ/G1AQhT3QgAhcGuKtJcy0nS80mSZaqERtzvHR/a6nMo
GWbKv/x/ce6MpagILXPI/vSySjbIj4/7uYxrrwbN3Yanj0nVG6/TbCih1/t46RVS
KbT0H8HCLHeHOP+yiSFz/D3cLjA+WL1RffKNfFTFRZ9v3TOOg+5h9wnNOjHHqTWL
The Jackal, holding the radio right behind Aleph One
https://www.defcon.org/images/graphics/PICTURES/defcar1.jpg
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.7.0 (Build 1012)
Charset: us-ascii
wsBVAwUBSAAJNA6+AoIwjTCUAQhcvgf/aaJaaWHmGbNjcM8vkzB1R5HpDCals9KR
IXjKofT/Ws+ILtU2JuTmBMDjPno+pM0eKmEkb+8ujedfQ19hZ8STy8OIi/z+rEs9
/heEuB1tzreMXKoEckGgJuLcTLpUjdVveQ3VGVdVO9NZAYz11bjtL1esrAziEZwx
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFMffLsS2KysvBH1xkRAtB/AJ9K+rNPCM9bWOlJPTWxS31Sk+4xHACfelfz
UiktBThlml9iUQfdg4eXoTQ=
=WdND
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFMffPwS2KysvBH1xkRAvXwAJ4skfzL8KP0a0OFA3VrUwSN0zMB6wCcC/yB
xiPGukMjKtDy6B2f6/hB/LE=
=PAp4
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2011 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFOi+JjDEcm8Vbi9kMRAtdxAKDi6DmTvnmL3zhQ+i0Oa4qtMfZS3gCfWEYL
LvAZ37RkpYqCWsk1HDvl7B8=
=uK4e
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFMO/mBS2KysvBH1xkRAuk8AJ47bVVbirFHy9YV7tlkEjBnqoFn/ACfXbmH
MpvA3yOeQCEdX/rTqVFF+zY=
=Wn5B
Copyright 2011 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFNJBPaS2KysvBH1xkRAtseAJ4l2OJWnrpwT9YcncIzlZU66/imEgCfUBzL
wDKHxW0zrjUpSyFjUvC87Nk=
=28bu
The Jackal, holding the radio right behind Aleph One
https://www.defcon.org/images/graphics/PICTURES/defcar1.jpg
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.7.0 (Build 1012)
Charset: us-ascii
wsBVAwUBSAAJNA6+AoIwjTCUAQhcvgf/aaJaaWHmGbNjcM8vkzB1R5HpDCals9KR
IXjKofT/Ws+ILtU2JuTmBMDjPno+pM0eKmEkb+8ujedfQ19hZ8STy8OIi/z+rEs9
/heEuB1tzreMXKoEckGgJuLcTLpUjdVveQ3VGVdVO9NZAYz11bjtL1esrAziEZwx
on, this information.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 10.0.1 (Build 4020)
Charset: utf-8
wsBVAwUBS5Ds3LoMEKjkBtO0AQgh9wf+JnKBe4/T1gaMqq1iblKrAE4HBd829G06
Z4h2WawQ5DVp5FHR7sKtM7bldXbwML/fdyTsWD8R/EJ3DAJI/zqUuYqDt9Ur5aWz
yB8aWU8QyiPwFTOWz8s2kUjl9VOnmEb6Rwtpn+jS1RoRCV/6AX8/uRS/UKOsznaD
remains to be seen."
- - ferg
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)
wj8DBQFIn+HCq1pz9mNUZTMRAg5bAKC14z8wNBom1TASstp9D6n3fL4bLwCfSzxU
cQcPfvWSi7j3Bwpgy1hPZJM=
=5lFT
-----END PGP SIGNATURE-----
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFMRHzZS2KysvBH1xkRAmGOAJ9NP3RuHj2w4mwu3saJFdjce+PrqwCfXhLk
kQ3DQOJquo4Ymo7foPajEwY=
=iZyn
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFLj1c6S2KysvBH1xkRAnl5AJ9RcHVB7qooSwOPFdVoDFTjohDypgCfZ44O
2z0ICIcntM88ZONMfDNUM6Y=
=14fN
Copyright 2009 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFKSwuTS2KysvBH1xkRAoUdAJ9p880DOAAa1Eey+EhEYJKQwuHLtgCfVBku
2uDpvVwMPaKZA6dcNPJxENc=
=GMve
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2009 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFK50xMS2KysvBH1xkRAtDQAJ4j8i4FSanVEdj2zXOKGhz+jCN9ogCeJTow
ByoB8aJdMwQ3mswOBWDjR5k=
=0Ncp
EMC Product Security Response Center
Security_Alert@EMC.com
http://www.emc.com/contact-us/contact/product-security-response-center.htm
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)
wj8DBQFO8Nt1tjd2rKp+ALwRAlCOAKCnyEZXtgtPa+he2x0om8OW88i/zACeIMeV
UOJkdbtPmzbQrix7DSaHZZM=
=nHw+
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003) - not licensed for commercial
use: www.pgp.com
wsBVAwUBSKSBzGl+Jnd3SMmAAQhJPAgAq4SY+PG0ONFUsJDMWmadjKnG+LUSbyg6
Fnr/Up7HF59Z61r6/NXUG2TiUccu8u/ZE2ew7aUteAvbRM4sUWuQBlGXTRwgtv6S
PKxOCQ5luLJjxDN9cKCN5KfpMmkCazoUXgno1PblKQH9CSxmZJxipsDWDLTMJHfU
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2011 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFNuZubDEcm8Vbi9kMRAnwpAKDmLblfA++OHuWKEOiOzXmayf3JEgCgwfbN
kr36WEecIMy3XzvjG84ikVM=
=9R0l
The original DEF CON 1 pic I was looking for..
https://www.defcon.org/images/graphics/PICTURES/defcar1.jpg
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.7.0 (Build 1012)
Charset: us-ascii
wsBVAwUBSAF1NQ6+AoIwjTCUAQjskAgAjVYLcnkTCgffx17F70NKbugGjs9fmar5
nrnu2FIJS+Lase2xWy+vs6TBGMVGwWQxHIRYgR1UFAQIbVu4OPXP/LNCrFZFLpf6
Nn6Y2qey5ZH+0vjv3h2g3fGi741vJvuayLJ5zd9DlAHItFMDechkS4zi54uesHdK
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2010 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFLsY4wS2KysvBH1xkRAv1RAJ9ELh3jWg7ZQsZNgTy7nuM2Rj8NjACfTub2
FRjw4Mfsh3658XAzuC1bsJg=
=PL0U
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2011 VMware Inc. All rights reserved.
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj8DBQFNfoXpS2KysvBH1xkRAiuiAJ9nyIgRIEiD4kYI7ZODRu/m0iJOQgCeIbKD
J0gV3DRUWD3NMkMKC/ysvZE=
=8K7w
http://www.ysts.org
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8
wj4DBQFLFtSVgo//xpeLCaoRAifVAJ9h64bItt8uJm5jd0LHeBvtHnowywCYs0yn
xXQipA3mFPq+OwtStCNwEg==
=7Pjd
Next Page>>
|