Vulnerability Bulletins |
Vulnerabilidad en Symantec PGP Desktop y Encryption Desktop |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | official+tested |
| Impact | Aumento de privilegios |
| Dificulty | Avanzado |
| Required attacker level | Acceso fisico |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software |
Symantec Encryption Desktop 10.3.0 Symantec Pgp Desktop 10.2.1 Symantec Pgp Desktop 10.2.0 Symantec Pgp Desktop 10.1.2 Symantec Pgp Desktop 10.1.1 |
Description |
|
| Se ha descubierto una vulnerabilidad de desbordamiento de enteros en el fichero pgpwded.sys en Symantec PGP Desktop v10.x y Encryption Desktop v10.3.0, versiones anteriores a MP1, que permite a atacantes locales aumentar sus privilegios mediante una aplicación especialmente diseñada. | |
Solution |
|
| Aplicar la actualización publicada por Symantec. | |
Standar resources |
|
| Property | Value |
| CVE |
CVE-2012-4351 CVE-2012-6533 |
| BID |
BID 57170 BID 57835 |
Other resources |
|
|
Security Advisories Relating to Symantec Products - Symantec Encryption Desktop Local Access Elevation of Privilege http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2013&suid=20130213_00 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2013-03-18 |






