CVE-2009-3028
Summary
| CVE | CVE-2009-3028 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-03-07 21:00:00 UTC |
| Updated | 2013-02-07 04:21:00 UTC |
| Description | The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 57893 | OSVDB | www.osvdb.org | |
| Altirix eXpress NS SC Download ActiveX Control "DownloadAndInstall()" Insecure Method - Secunia Advisories - Vulnerability Information - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| Broadcom Support Portal | CONFIRM | www.symantec.com | |
| Enterprise Support - Symantec Corp. - Vulnerability in the Altiris eXpress NS SC Download ActiveX control | CONFIRM | www.symantec.com | Patch |
| Symantec Altiris eXpress NS SC Download ActiveX Control Arbitrary File Download Vulnerability | BID | www.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.