« Volver al listado

CVE-2014-3431

Estado: ModificadaMedia (4.3)—

Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3431",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-06-21T15:55:04.680",
  "references": [
    {
      "url": "http://secunia.com/advisories/59421",
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/68077",
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1030454",
      "source": "secure@symantec.com"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140620_00",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "http://secunia.com/advisories/59421",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/68077",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1030454",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140620_00",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Symantec PGP Desktop 10.x, y Encryption Desktop Professional 10.3.x anterior a 10.3.2 MP2, en OS X utiliza permisos de lectura universal para ficheros temporales, lo que permite a usuarios locales evadir restricciones sobre la lectura de ficheros, modificación, creación y cambios de permisos a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:08:10.420",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:encryption_desktop:10.3.0:*:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E73390D3-3DE8-43AB-980F-0885A6C57A08"
            },
            {
              "criteria": "cpe:2.3:a:symantec:encryption_desktop:10.3.1:*:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C641BF3B-033C-4E89-99D1-D0279176E85B"
            },
            {
              "criteria": "cpe:2.3:a:symantec:encryption_desktop:10.3.2:-:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D80F9A3B-E810-422C-9168-B58ADC983A9F"
            },
            {
              "criteria": "cpe:2.3:a:symantec:encryption_desktop:10.3.2:mp1:*:*:professional:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64884C14-9E0D-4C8E-802E-D373DE80A506"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EBF6909-8372-4264-8510-53482589D3D4"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A873C35-C480-4A3D-A0B2-5BDAF794B80C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D7928F8-9E18-495B-AF0A-FE64B3CA88A0"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59BEA5BE-2595-4BE5-B0CC-405748925F9E"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFA810A7-C21B-4314-88CE-CC0018D6209F"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D6C464E-45C2-44B7-B474-4165C7FF9FE7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38F4B912-92AA-4438-80EE-C3C46775D59C"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E5D7E1B-44AE-4EB7-940C-7010D92A1CFC"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B704ED7-8438-4BCF-B062-5303C3D9CAAB"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pgp_desktop:10.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01D5E4E1-B128-4E77-A137-BA435082720C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0FF5999A-9D12-4CDD-8DE9-A89C10B2D574"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}