Vulnerability CVE-2014-3436


Published: 2014-08-21   Modified: 2014-08-22

Description:
Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Symantec -> Encryption desktop 
Symantec -> Pgp desktop 

 References:
http://www.securityfocus.com/bid/69259
http://www.securitytracker.com/id/1030761
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140821_00
http://xforce.iss.net/xforce/xfdb/95406

Copyright 2024, cxsecurity.com

 

Back to Top