PGP 5.x/6.x/7.0 - ASCII Armor Parser Arbitrary File Creation

EDB-ID:

20738




Platform:

Multiple

Date:

2001-04-09


source: https://www.securityfocus.com/bid/2556/info

ASCII Armor is a text based encoding format used by PGP (Pretty Good Privacy). While it is possible to encode any file using ASCII Armor, it is used by PGP to encode signature files and public keys to facilitate transmission in e-mail messages.

When a user opens a document for verification in PGP, its corresponding .sig file must be decoded from ASCII Armor.

Due to a flaw in the implementation of the decoder, an arbitrary file can be created on a users system. The file created would be of the attackers choice. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/20738.doc.sig