LOW · 2.6

CVE-2014-1647

Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of ser...

Vulnerability Description

Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
SymantecPgp Desktop10.0.0
SymantecEncryption Desktop10.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1647?

CVE-2014-1647 is a vulnerability with a CVSS score of 2.6 (LOW). Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of ser...

How severe is CVE-2014-1647?

CVE-2014-1647 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1647?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Pgp Desktop, Symantec Encryption Desktop.