
CVE-2009-3108
https://notcve.org/view.php?id=CVE-2009-3108
08 Sep 2009 — The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program. Aclient GUI en Symantec Altiris Deployment Solution v6.9.x anterior v6.9 SP3 Build 430 instala un cliente ejecutable con permisos no seguros (todos: control total), que permite a usuarios locales obtener privilegios y reemplazar el ejecutable c... • http://secunia.com/advisories/36502 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2009-3109
https://notcve.org/view.php?id=CVE-2009-3109
08 Sep 2009 — Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed. Vulnerabilidad no especificada en el agente AClient en Symantec Altiris Deployment Solution v6.9.x anteriores a 6.9... • http://secunia.com/advisories/36502 •

CVE-2009-3110
https://notcve.org/view.php?id=CVE-2009-3110
08 Sep 2009 — Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does. Condición de carrera en la funcionalidad de transferencia de ficheros en Symantec Altiris Deployment Solution v6.9.x anterior a v6.9 SP3 Build 430, permite a atacantes remotos leer archivos sensibles y prevenir las actualizaciones de los clien... • http://secunia.com/advisories/36502 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2008-6827
https://notcve.org/view.php?id=CVE-2008-6827
08 Jun 2009 — The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function. El control "ListView" (vista de lista) del cliente de interfaz gráfico (AClient.exe) en Altiris ... • https://github.com/alt3kx/CVE-2008-6827 • CWE-306: Missing Authentication for Critical Function •

CVE-2008-6828
https://notcve.org/view.php?id=CVE-2008-6828
08 Jun 2009 — Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server. Altiris Deployment Solution v6.x anterior a 6.9.355 SP1 de Symantec almacena la contraseña de "Application Identity Account" (cuenta de identidad de aplicación) en texto claro, lo que permite a usuarios locales obtener privilegios y modificar clientes de "Deployment Solution Serve... • http://secunia.com/advisories/31773 • CWE-312: Cleartext Storage of Sensitive Information •

CVE-2008-4564
https://notcve.org/view.php?id=CVE-2008-4564
18 Mar 2009 — Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file. Desbordamiento de búfer basado en pila en wp6sr.dll en el Autonomy KeyView SDK 10.4 y anteriores, como es usado en IBM Lotus Notes, productos Symantec Mail Security (SMS)... • http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=774 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-2287
https://notcve.org/view.php?id=CVE-2008-2287
18 May 2008 — Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse. Symantec Altiris Deployment Solution 6.8.x y 6.9.x anterior a 6.9.176 no protege correctamente el directorio install, lo que podría permitir a usuarios locales obtener privilegios reemplazando un componente de una aplicación por un troyano. • http://marc.info/?l=bugtraq&m=122167472229965&w=2 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-2288
https://notcve.org/view.php?id=CVE-2008-2288
18 May 2008 — Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information. Symantec Altiris Deployment Solution 6.8.x y 6.9.x anterior a 6.9.176 no tiene suficiente control de acceso para eliminación y modificación de claves de registro, que permite a usuarios locales provocar una denegación de servicio u obtener información sensible. • http://marc.info/?l=bugtraq&m=122167472229965&w=2 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-2289
https://notcve.org/view.php?id=CVE-2008-2289
18 May 2008 — Unspecified vulnerability in a tooltip element in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors. Vulnerabilidad no especificada en un elemento tooltip en Symantec Altiris Deployment Solution 6.8.x y 6.9.x anterior a 6.9.176 permite a usuarios locales obtener privilegios mediante vectores de ataque desconocidos. • http://marc.info/?l=bugtraq&m=122167472229965&w=2 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2008-2290
https://notcve.org/view.php?id=CVE-2008-2290
18 May 2008 — Unspecified vulnerability in the Agent user interface in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors. Vulnerabilidad sin especificar en la interfaz de usuario Agent de Symantec Altiris Deployment Solution 6.8.x y 6.9.x anterior a 6.9.176 permite a usuarios locales obtener privilegios mediantes vectores de ataque desconocidos. • http://marc.info/?l=bugtraq&m=122167472229965&w=2 • CWE-264: Permissions, Privileges, and Access Controls •