Symantec LiveUpdate Client Local Information Disclosure Vulnerability
BID:14708
Info
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
| Bugtraq ID: | 14708 |
| Class: | Design Error |
| CVE: |
CVE-2005-2766 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 31 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Symantec LiveUpdate 2.7 build 34 Symantec AntiVirus Corporate Edition 9.0.4 Symantec AntiVirus Corporate Edition 9.0.1 .1.1000 |
| Not Vulnerable: |
Symantec LiveUpdate 2.7 build 38 Symantec LiveUpdate 2.6 Symantec LiveUpdate 2.5 |
Discussion
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability.
Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file.
A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server.
Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability.
Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file.
A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server.
Exploit / POC
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
Solution:
An update is available:
Symantec LiveUpdate 2.7 build 34
Solution:
An update is available:
Symantec LiveUpdate 2.7 build 34
-
Symantec lusetup.exe
http://www.symantec.com/techsupp/files/lu/lu.html
References
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
References:
References: