Computer Security
[EN] securityvulns.ru
no-pyccku



Symantec PCAnywhere multiple security vulnerabilities
updated since 30.01.2012
Published:01.05.2012
Source:BUGTRAQ
SecurityVulns ID:12163
Type:remote
Level:7/10
Description:Code execution, privilege escalation.
Affected:SYMANTEC : pcAnywhere 12.5
 SYMANTEC : IT Management Suite 7.0
 SYMANTEC : IT Management Suite 7.1
CVE:CVE-2011-3478 (The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.)
Original documentdocumentResearch@NGSSecure, NGS00117 Technical Advisory: Symantec pcAnywhere insecure file permissions local privilege escalation (01.05.2012)
 documentResearch@NGSSecure, NGS00118 Technical Advisory: Symantec pcAnywhere Remote Code Execution as SYSTEM (01.05.2012)
 documentResearch@NGSSecure, ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability (30.01.2012)
 documentResearch@NGSSecure, NGS00117 Patch Notification: Symantec PCAnywhere Local Privilege Escalation (30.01.2012)
 documentResearch@NGSSecure, NGS00118 Patch Notification: Symantec PCAnywhere Remote Code Execution as SYSTEM (30.01.2012)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru