Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

 
NetNews
N E W S / A N A L Y S I S  


NAI Follows Through

  October 10, 2002
  By Mike Fratto


A buffer overflow has been discovered by Foundstone in all versions of Pretty Good Privacy Corporate Desktop 7.1. And Network Associates has issued a hot fix.

The overflow occurs when PGP Corporate Desktop tries to decrypt a PGP archive that contains a file name with more than 200 characters. Foundstone was able to run arbitrary code by sending a PGP-encrypted archive containing a long file name using a proof-of-concept exploit the vendor developed.

It's commendable that even though Network Associates is in the process of divesting itself of interests in PGP, it researched the problem and issued a patch. NAI could have passed the problem off to PGP Corp. In the turmoil of a company transition, the vulnerability may not have received the attention it deserved.

That's not to say that NAI jumped on the problem without prodding. Foundstone did have to get to the right person at NAI. But this event serves as a good example of responsible disclosure. All vendors should be so responsive

--Mike Fratto


Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers