Key Management Vulnerability in Symantec PGP Universal Server and Encryption Management Server
CVE-2014-7287
Currently unrated
Key Information:
- Vendor
- Symantec
- Vendor
- CVE Published:
- 1 February 2015
Summary
The key-management component in Symantec's PGP Universal Server and Encryption Management Server prior to version 3.3.2 MP7 is susceptible to a flaw that enables remote attackers to inject unintended content into outbound email messages. This vulnerability can be exploited through a specially crafted key UID value within an inbound email, potentially affecting the integrity of the Subject header and other email fields, leading to various security risks.
References
Timeline
Vulnerability published
Vulnerability Reserved