The three-year-old flaw, not publicized until Thursday, lets an attacker decrypt PGP data but does not let the attacker impersonate the PGP certificate holder, Jones emphasizes.
CNN: Technology - Security flaw discovered in Network Associates PGP software