CVE-2012-3582: Low severity symantec pgp universal server vulnerability
Published Sep 4, 2012
·Updated
Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session.
Affected Software
2 affected components
Symantec PGP Universal Server=3.2.0
Symantec PGP Universal Server=3.2.1
Event History
Sep 4, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3582?
CVE-2012-3582 is rated as medium severity due to potential exposure of private keys.
2
How do I fix CVE-2012-3582?
To mitigate CVE-2012-3582, upgrade to Symantec PGP Universal Server version 3.2.1 MP2 or later.
3
What are the implications of exploiting CVE-2012-3582?
Exploitation of CVE-2012-3582 could allow attackers to read private keys under specific circumstances.
4
What versions of Symantec PGP Universal Server are affected by CVE-2012-3582?
CVE-2012-3582 affects Symantec PGP Universal Server versions 3.2.0 and 3.2.1 before MP2.
5
Is CVE-2012-3582 a local or remote vulnerability?
CVE-2012-3582 is considered a remote vulnerability as it allows external attackers to exploit it.