CVE-2012-4351: Integer Overflow
Published Feb 18, 2013
·Updated
Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a crafted application.
Affected Software
10 affected components
Symantec Encryption Desktop=10.3.0
Symantec Pgp Desktop Windows=10.0.0
Symantec Pgp Desktop Windows=10.0.1
Symantec Pgp Desktop Windows=10.0.2
Symantec Pgp Desktop Windows=10.0.3
Symantec Pgp Desktop Windows=10.1.0
Symantec Pgp Desktop Windows=10.1.1
Symantec Pgp Desktop Windows=10.1.2
Symantec Pgp Desktop Windows=10.2.0
Symantec Pgp Desktop Windows=10.2.1
Event History
Feb 18, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4351?
CVE-2012-4351 has a moderate severity rating due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2012-4351?
To fix CVE-2012-4351, update Symantec Encryption Desktop or PGP Desktop to the latest version that addresses this vulnerability.
3
Which products are affected by CVE-2012-4351?
CVE-2012-4351 affects Symantec PGP Desktop versions 10.0.0 through 10.2.1 and Symantec Encryption Desktop version 10.3.0 prior to MP1.
4
Can CVE-2012-4351 be exploited remotely?
CVE-2012-4351 cannot be exploited remotely as it requires local access to the system.
5
What type of vulnerability is CVE-2012-4351?
CVE-2012-4351 is classified as an integer overflow vulnerability.