First published: Tue Sep 04 2012(Updated: )
Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec PGP Universal Server | =3.2.0 | |
Symantec PGP Universal Server | =3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3582 is rated as medium severity due to potential exposure of private keys.
To mitigate CVE-2012-3582, upgrade to Symantec PGP Universal Server version 3.2.1 MP2 or later.
Exploitation of CVE-2012-3582 could allow attackers to read private keys under specific circumstances.
CVE-2012-3582 affects Symantec PGP Universal Server versions 3.2.0 and 3.2.1 before MP2.
CVE-2012-3582 is considered a remote vulnerability as it allows external attackers to exploit it.