Описание
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.
Ссылки
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.3.2 (включая)Версия до 3.3.2 (включая)
Одно из
cpe:2.3:a:symantec:encryption_management_server:*:mp6:*:*:*:*:*:*
cpe:2.3:a:symantec:pgp_universal_server:*:mp6:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00513
Низкий
5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
github
около 3 лет назад
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.
EPSS
Процентиль: 65%
0.00513
Низкий
5 Medium
CVSS2
Дефекты
CWE-74