Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
BID:33247
Info
Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 33247 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4388 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2009 12:00AM |
| Updated: | Jan 19 2009 05:42PM |
| Credit: | Will Dormann of CERT |
| Vulnerable: |
Symantec AppStream Client 5.2 |
| Not Vulnerable: |
Symantec AppStream Client 5.2.2 SP3 MP1 |
Discussion
Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
Symantec AppStream Client is prone to a vulnerability that can allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Symantec AppStream Client is prone to a vulnerability that can allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Exploit / POC
Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Symantec AppStream Client 'LaunchObj' ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- AppStream Client Homepage (Symantec)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vulnerability Note VU#194505 (US-CERT)
- SYM09-001: Symantec AppStream ActiveX Unauthorized Access (Symantec)