Symantec pcAnywhere Insecure File Permissions Vulnerability
BID:51593
Info
Symantec pcAnywhere Insecure File Permissions Vulnerability
| Bugtraq ID: | 51593 |
| Class: | Design Error |
| CVE: |
CVE-2011-3479 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 23 2012 12:00AM |
| Updated: | Apr 09 2012 10:00PM |
| Credit: | Edward Torkington |
| Vulnerable: |
Symantec pcAnywhere Solution 12.6 Symantec pcAnywhere Solution 12.5 Symantec pcAnywhere 11.5.1 Symantec pcAnywhere 11.5 Symantec pcAnywhere 11.0.1 Symantec pcAnywhere 11.0 Symantec pcAnywhere 10.5 Symantec pcAnywhere 10.0 Symantec pcAnywhere 12.5 SP3 Symantec pcAnywhere 12.5 SP1 Symantec pcAnywhere 12.5 Symantec pcAnywhere 12.1 Symantec pcAnywhere 12.0 |
| Not Vulnerable: |
Symantec pcAnywhere Solution 12.6.7 Symantec pcAnywhere 12.5 SP4 |
Discussion
Symantec pcAnywhere Insecure File Permissions Vulnerability
pcAnywhere is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to overwrite specific files with arbitrary data. This may aid the attacker in gaining elevated privileges.
pcAnywhere 12.5 versions are affected; other versions may also be affected.
pcAnywhere is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to overwrite specific files with arbitrary data. This may aid the attacker in gaining elevated privileges.
pcAnywhere 12.5 versions are affected; other versions may also be affected.
Exploit / POC
Symantec pcAnywhere Insecure File Permissions Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
Symantec pcAnywhere Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Symantec pcAnywhere Insecure File Permissions Vulnerability
References:
References:
- pcAnywhere Homepage (Symantec)
- pcAnywhere hotfix (Symantec)
- SYM12-002 Security Advisories Relating to Symantec Products - Symantec pcAnywher (Symantec)