pcAnywhere Authentication Denial of Service Vulnerability
BID:15646
Info
pcAnywhere Authentication Denial of Service Vulnerability
| Bugtraq ID: | 15646 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3934 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2005 12:00AM |
| Updated: | Feb 07 2006 08:55PM |
| Credit: | Credited to Tal of See-Security technologies Ltd. |
| Vulnerable: |
Symantec pcAnywhere 11.5.1 Symantec pcAnywhere 11.5 Symantec pcAnywhere 11.0.1 Symantec pcAnywhere 11.0 Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 Symantec pcAnywhere 9.2 Symantec pcAnywhere 9.0.1 Symantec pcAnywhere 9.0 Symantec pcAnywhere 8.0.2 Symantec pcAnywhere 8.0.1 |
| Not Vulnerable: | |
Discussion
pcAnywhere Authentication Denial of Service Vulnerability
Symantec pcAnywhere is vulnerable to a buffer overflow vulnerability. Because the flaw can be triggered prior to authentication, the vulnerability is exploitable by remote attackers without valid credentials. It is confirmed that the vulnerability can be exploited to cause a denial of service. Supported versions 11.0.1 and 11.5.1 are confirmed affected. Previous versions are vulnerable and users are advised to upgrade to the latest supported version.
Patches are available.
Symantec pcAnywhere is vulnerable to a buffer overflow vulnerability. Because the flaw can be triggered prior to authentication, the vulnerability is exploitable by remote attackers without valid credentials. It is confirmed that the vulnerability can be exploited to cause a denial of service. Supported versions 11.0.1 and 11.5.1 are confirmed affected. Previous versions are vulnerable and users are advised to upgrade to the latest supported version.
Patches are available.
Exploit / POC
pcAnywhere Authentication Denial of Service Vulnerability
An exploit (pcanywhere_dos.pl) has been supplied by David Maciejak.
Exploit code (pcanywhere_dos.pl) has been updated.
An exploit (pcanywhere_dos.pl) has been supplied by David Maciejak.
Exploit code (pcanywhere_dos.pl) has been updated.
Solution / Fix
pcAnywhere Authentication Denial of Service Vulnerability
Solution:
Patches are available at the following locations.
Consumer versions of pcAnywhere:
http://www.symantec.com/techsupp/files/pca/index.html
Enterprise versions of pcAnywhere:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html
Solution:
Patches are available at the following locations.
Consumer versions of pcAnywhere:
http://www.symantec.com/techsupp/files/pca/index.html
Enterprise versions of pcAnywhere:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html
References
pcAnywhere Authentication Denial of Service Vulnerability
References:
References:
- Symantec pcAnywhere Denial of Service (Symantec)