Session Management Flaw in Symantec PGP Universal Server
CVE-2012-3582
Currently unrated
Summary
The Symantec PGP Universal Server 3.2.x versions prior to 3.2.1 MP2 exhibit inadequate session management during key search requests. This oversight allows remote attackers the potential to access private keys if a request is made towards the end of an active user session. It underscores the critical importance of robust session handling mechanisms to safeguard sensitive cryptographic information.
References
Timeline
Vulnerability published
Vulnerability Reserved