PT-2009-5368 · Symantec · Symantec Management Platform+2

Nikolas Sotiriu

·

Publicado

2009-11-03

·

Atualizado

2018-10-10

·

CVE-2009-3031

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Symantec Altiris Notification Server (NS) versions 6.0.0.1846 through 6.0 before R12 Symantec Altiris Deployment Solution versions 6.8 and 6.9 in Deployment Server Symantec Management Platform (SMP) versions 7.0 through 7.0 before SP3
Description: The issue is a stack-based buffer overflow in the BrowseAndSaveFile method within the Altiris eXpress NS ConsoleUtilities ActiveX control. This allows remote attackers to execute arbitrary code via a long string in the second argument to the BrowseAndSaveFile method.
Recommendations: For Symantec Altiris Notification Server (NS) versions 6.0.0.1846 through 6.0 before R12, update to R12 or later. For Symantec Altiris Deployment Solution versions 6.8 and 6.9 in Deployment Server, consider disabling the BrowseAndSaveFile method until a patch is available. For Symantec Management Platform (SMP) versions 7.0 through 7.0 before SP3, update to SP3 or later.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3031

Produtos afetados

Symantec Altiris Deployment Solution
Symantec Altiris Notification Server
Symantec Management Platform