Symantec pcAnywhere Local Format String Vulnerability
BID:33845
Info
Symantec pcAnywhere Local Format String Vulnerability
| Bugtraq ID: | 33845 |
| Class: | Design Error |
| CVE: |
CVE-2009-0538 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 17 2009 12:00AM |
| Updated: | Mar 18 2009 02:56PM |
| Credit: | Deral Heiland from Layered Defense |
| Vulnerable: |
Symantec pcAnywhere 12.5 Symantec pcAnywhere 12.1 Symantec pcAnywhere 12.0 |
| Not Vulnerable: |
Symantec pcAnywhere 12.5 SP1 |
Discussion
Symantec pcAnywhere Local Format String Vulnerability
Symantec pcAnywhere is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
pcAnywhere 12.0, 12.1, and 12.5 are vulnerable; other versions may also be affected.
Symantec pcAnywhere is prone to a local format-string vulnerability.
A local attacker may exploit this issue to crash the affected application, resulting in a denial-of-service condition. The attacker may also be able to execute arbitrary code within the context of the application, but this has not been confirmed.
pcAnywhere 12.0, 12.1, and 12.5 are vulnerable; other versions may also be affected.
Exploit / POC
Symantec pcAnywhere Local Format String Vulnerability
Attackers can use readily available command-line tools to exploit this issue.
Attackers can use readily available command-line tools to exploit this issue.
Solution / Fix
Symantec pcAnywhere Local Format String Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
Symantec pcAnywhere Local Format String Vulnerability
References:
References: