CVE-2012-3582
Symantec PGP Universal Server 3.2.x < 3.2.1 MP2 - Unauthenticated Private Key Exposure via Key Search Request
Title source: llmDescription
Symantec PGP Universal Server 3.2.x before 3.2.1 MP2 does not properly manage sessions that include key search requests, which might allow remote attackers to read a private key in opportunistic circumstances by making a request near the end of a user's session.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120830_00
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1027467
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55246
Scores
EPSS
0.0022
EPSS Percentile
45.0%
Details
CWE
CWE-264
Status
published
Products (2)
symantec/pgp_universal_server
3.2.0
symantec/pgp_universal_server
3.2.1
Published
Sep 04, 2012
Tracked Since
Feb 18, 2026