Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
BID:36698
Info
Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 36698 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3031 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2009 12:00AM |
| Updated: | Nov 02 2009 10:47PM |
| Credit: | Nikolas Sotiriu |
| Vulnerable: |
Symantec Management Platform 7.0 SP1 Symantec Management Platform 7.0 Symantec Altiris Notification Server 6.0 SP3 R7 Symantec Altiris Notification Server 6.0 SP3 Symantec Altiris Notification Server 6.0 SP2 Symantec Altiris Notification Server 6.0 SP1 Symantec Altiris Notification Server 6.0 Symantec Altiris Deployment Solution 6.9.355 SP1 Symantec Altiris Deployment Solution 6.9.355 Symantec Altiris Deployment Solution 6.9.176 Symantec Altiris Deployment Solution 6.9.164 Symantec Altiris Deployment Solution 6.9 SP3 Build 430 Symantec Altiris Deployment Solution 6.9 SP1 Symantec Altiris Deployment Solution 6.9 |
| Not Vulnerable: | |
Discussion
Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
Symantec Altiris Notification Server with Symantec Management Platform and Altiris Deployment Solution are prone to a buffer-overflow vulnerability because the applications use an ActiveX control provided by 'AeXNSConsoleUtilities.dll' that fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Symantec Altiris Notification Server with Symantec Management Platform and Altiris Deployment Solution are prone to a buffer-overflow vulnerability because the applications use an ActiveX control provided by 'AeXNSConsoleUtilities.dll' that fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Symantec Altiris Deployment Solution 6.9 SP1
Symantec Altiris Deployment Solution 6.9
Symantec Altiris Deployment Solution 6.9 SP3 Build 430
Symantec Altiris Deployment Solution 6.9.164
Symantec Altiris Deployment Solution 6.9.176
Symantec Altiris Deployment Solution 6.9.355
Symantec Altiris Deployment Solution 6.9.355 SP1
Solution:
Updates are available. Please see the references for details.
Symantec Altiris Deployment Solution 6.9 SP1
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9 SP3 Build 430
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9.164
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9.176
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9.355
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
Symantec Altiris Deployment Solution 6.9.355 SP1
-
Symantec AltirisNSConsole.zip
https://kb.altiris.com/utility/getfile.asp?rid=6364&aid=49568
References
Multiple Symantec Altiris Products ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Symantec Homepage (Symantec)
- NSOADV-2009-001: Symantec ConsoleUtilities ActiveX Control Buffer Overflow (NSO Research
) - Security Advisories Relating to Symantec Products - Symantec Altiris Deployment (Symantec)
- Symantec ConsoleUtilities ActiveX Control Buffer Overflow (Nikolas Sotiriu)
- Vulnerability in the Altiris Deployment Server Web Console (Symantec)
- Vulnerability in the Altiris eXpress NS Console Utilities ActiveX control (Symantec)