Description
Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67020
Vendor Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140423_00
Scores
EPSS
0.0032
EPSS Percentile
54.9%
Details
CWE
CWE-119
Status
published
Products (13)
symantec/encryption_desktop
10.3.0
symantec/encryption_desktop
10.3.1
symantec/encryption_desktop
10.3.2
symantec/pgp_desktop
10.0.0
symantec/pgp_desktop
10.0.1
symantec/pgp_desktop
10.0.2
symantec/pgp_desktop
10.0.3
symantec/pgp_desktop
10.1.0
symantec/pgp_desktop
10.1.1
symantec/pgp_desktop
10.1.2
... and 3 more
Published
Apr 23, 2014
Tracked Since
Feb 18, 2026