CVE-2009-3033
Summary
| CVE | CVE-2009-3033 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-25 16:30:00 UTC |
| Updated | 2017-08-17 01:31:00 UTC |
| Description | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kb.altiris.com/article.asp | CONFIRM | kb.altiris.com | Patch, Vendor Advisory |
| kb.altiris.com/article.asp | CONFIRM | kb.altiris.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 60496 | OSVDB | osvdb.org | |
| Multiple Symantec Altiris Products 'RunCmd()' ActiveX Control Buffer Overflow Vulnerability | BID | www.securityfocus.com | Exploit, Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Security Advisories Relating to Symantec Products - Symantec’s Altiris Deployment and Notification Management Web Console RunCmd Vulnerability - 2009-11-24T09:17:16 PST | Symantec | CONFIRM | www.symantec.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.