Description Preview
Symantec PGP Desktop versions 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 are affected by a vulnerability that allows remote attackers to cause a denial of service by triggering a read access violation and application crash through a malformed certificate.
Overview
This vulnerability in Symantec PGP Desktop and Encryption Desktop Professional versions allows remote attackers to exploit a flaw in the way block-data moves are performed, leading to a denial of service condition. The vulnerability was assigned CVE-2014-1647 and was made public on April 23, 2014.
Remediation
To remediate this issue, users are advised to update their Symantec PGP Desktop installations to version 10.3.2 MP1 or later. This update addresses the vulnerability by fixing the way block-data moves are handled, preventing remote attackers from causing a denial of service.
References
- CVE-2014-1647 Details: CVE-2014-1647
- Symantec Security Advisory: Symantec Security Advisory
- SecurityFocus BID: BID-67020
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Finance and InsuranceFinance and Insurance
- Public AdministrationPublic Administration
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Educational ServicesEducational Services
- ManufacturingManufacturing
- Retail TradeRetail Trade
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade