Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
BID:72307
Info
Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
| Bugtraq ID: | 72307 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7287 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2015 12:00AM |
| Updated: | Jan 29 2015 12:00AM |
| Credit: | Klaus Eisentraut working through SySS GmbH |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
Symantec Encryption Management Server is prone to an email-header-injection vulnerability.
An attacker can exploit this issue to modify the content and perform unauthorized actions. This issue may also result in a segmentation fault.
The following products are vulnerable:
Versions prior to Symantec Encryption Management Server 3.3.2 MP6
Versions prior to Symantec PGP Universal Server 3.3.2 MP6
Symantec Encryption Management Server is prone to an email-header-injection vulnerability.
An attacker can exploit this issue to modify the content and perform unauthorized actions. This issue may also result in a segmentation fault.
The following products are vulnerable:
Versions prior to Symantec Encryption Management Server 3.3.2 MP6
Versions prior to Symantec PGP Universal Server 3.3.2 MP6
Exploit / POC
Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Encryption Management Server CVE-2014-7287 Email Header Injection Vulnerability
References:
References:
- Symantec Homepage (Symantec)