Skip to main content

Symantec plays down PGP hole

posted onJanuary 8, 2013
by l33tdawg

Symantec has quenched fears about a vulnerability in its PGP technology.

According to a Pastebin statement, the pgpwded.sys kernel driver distributed with Symantec PGP Desktop contains an arbitrary memory overwrite vulnerability in the handling of IOCTL 0x80022058.

While the statement admitted that an attacker would need local access to a vulnerable computer to exploit this vulnerability, successful exploitation of this issue would allow an attacker to execute arbitrary code. The statement also said that this vulnerability (METHO_BUFFERED with output_size == 0) exploit works only on Windows XP/2003.

Source

Tags

Symantec PGP Security

You May Also Like

Recent News

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th