Session Management Flaw in Symantec PGP Universal Server
CVE-2012-3582

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
4 September 2012

Summary

The Symantec PGP Universal Server 3.2.x versions prior to 3.2.1 MP2 exhibit inadequate session management during key search requests. This oversight allows remote attackers the potential to access private keys if a request is made towards the end of an active user session. It underscores the critical importance of robust session handling mechanisms to safeguard sensitive cryptographic information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.