|
|
|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-2766
The original article can be found at: http://www.securityfocus.com/bid/14708
|
| |
Vulnerable Systems:
* Symantec LiveUpdate 2.7 build 34
* Symantec AntiVirus Corporate Edition 9.0.4
* Symantec AntiVirus Corporate Edition 9.0.1 .1.1000
Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability.
Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file.
A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server.
Vendor Status:
Symantec as issued an update for this vulnerablity
Patch Availability:
http://securityresponse.symantec.com/avcenter/security/Content/2005.09.02.html
CVE Information:
CVE-2005-2766
|
|
|
|
|