Key Management Vulnerability in Symantec PGP Universal Server and Encryption Management Server
CVE-2014-7287

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
1 February 2015

Summary

The key-management component in Symantec's PGP Universal Server and Encryption Management Server prior to version 3.3.2 MP7 is susceptible to a flaw that enables remote attackers to inject unintended content into outbound email messages. This vulnerability can be exploited through a specially crafted key UID value within an inbound email, potentially affecting the integrity of the Subject header and other email fields, leading to various security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.