Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
BID:40611
Info
Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
| Bugtraq ID: | 40611 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4389 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2010 12:00AM |
| Updated: | Jun 17 2010 06:39PM |
| Credit: | Will Dormann of CERT |
| Vulnerable: |
Symantec Workspace Streaming 6.1 Symantec AppStream Client 5.2.2 Symantec AppStream Client 5.22 SP3 MP1 Symantec AppStream Client 5.2.2 SP3 MP1 Symantec AppStream Client 5.2 |
| Not Vulnerable: |
Symantec Workspace Streaming 6.1 SP4 |
Discussion
Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
Symantec Workspace Streaming (formerly Symantec AppStream) is prone to a vulnerability that can allow attackers to download and execute arbitrary files.
Successful exploits will allow malicious files to be downloaded and run with the privileges of the vulnerable application.
The following are vulnerable:
Symantec AppStream 5.2.x
Symantec Workspace Streaming 6.1.x prior to 6.1 SP4
Update (June 17, 2010): This issue may be exploited through a crafted web page which references a 'aswe://' URI; other vectors using the 'aswe' protocol handler may also exist.
Symantec Workspace Streaming (formerly Symantec AppStream) is prone to a vulnerability that can allow attackers to download and execute arbitrary files.
Successful exploits will allow malicious files to be downloaded and run with the privileges of the vulnerable application.
The following are vulnerable:
Symantec AppStream 5.2.x
Symantec Workspace Streaming 6.1.x prior to 6.1 SP4
Update (June 17, 2010): This issue may be exploited through a crafted web page which references a 'aswe://' URI; other vectors using the 'aswe' protocol handler may also exist.
Exploit / POC
Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Symantec Workspace Streaming Server Authentication Arbitrary File Download Vulnerability
References:
References: