PGP 5.x/6.x/7.0 - ASCII Armor Parser Arbitrary File Creation

Related Vulnerabilities: CVE-2001-0265  
Publish Date: 09 Apr 2001
Author: Chris Anley
                							

                source: http://www.securityfocus.com/bid/2556/info

ASCII Armor is a text based encoding format used by PGP (Pretty Good Privacy). While it is possible to encode any file using ASCII Armor, it is used by PGP to encode signature files and public keys to facilitate transmission in e-mail messages.

When a user opens a document for verification in PGP, its corresponding .sig file must be decoded from ASCII Armor.

Due to a flaw in the implementation of the decoder, an arbitrary file can be created on a users system. The file created would be of the attackers choice. 

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/20738.doc.sig