CVE-2012-0290
https://notcve.org/view.php?id=CVE-2012-0290
Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session." Symantec pcAnywhere hasta la versión v12.5.3, Altiris IT Management Suite pcAnywhere Soluction v7.0 (también conocido como v12.5.x) y v7.1 (también conocido como v12.6.x), Altiris Client Management Suite pcAnywhere Soluction v7.0 (también conocido como v12.5.x) y v7.1 (también conocido como v12.6.x) y Altiris Deployment Solution Remote pcAnywhere Solution v7.1 (también conocido como v12.5.x y v12.6.x) no manejan correctamente el estado del cliente después de la terminación anormal de una sesión remota, lo que permite a atacantes remotos obtener acceso al cliente aprovechandose de una "sesión de cliente abierta". • http://secunia.com/advisories/48092 http://www.securityfocus.com/bid/51862 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120124_00 https://exchange.xforce.ibmcloud.com/vulnerabilities/72996 •
CVE-2009-3028 – Symantec Altiris Deployment Solution - ActiveX Control Arbitrary File Download and Execute
https://notcve.org/view.php?id=CVE-2009-3028
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method. En Altiris eXpress NS SC la descarga del control ActiveX en AeXNSPkgDLLib.dll, como en Symantec Altiris Deployment Solution v6.9.x, Notification Server v6.0.x, y Symantec Management Platform v7.0.x expone un método inseguro, que permite a atacantes remotos forzar la descarga de archivos arbitrarios y, posiblemente, ejecutar código arbitrario a través del método DownloadAndInstall. • https://www.exploit-db.com/exploits/16600 http://secunia.com/advisories/36679 http://www.osvdb.org/57893 http://www.securityfocus.com/bid/36346 http://www.symantec.com/business/support/index?page=content&id=TECH44885 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090922_00 •
CVE-2009-3033 – Symantec Altiris Deployment Solution - ActiveX Control Buffer Overflow
https://notcve.org/view.php?id=CVE-2009-3033
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument. Desbordamiento de búfer en el método RunCmd en Altiris eXpress NS Console Utilities ActiveX control en AeXNSConsoleUtilities.dll en la consola web de Symantec Altiris Deployment Solution v6.9.x, Altiris Notification Server v6.0.x, y Management Platform v7.0.x permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga en el segundo argumento. • https://www.exploit-db.com/exploits/16528 http://osvdb.org/60496 http://www.securityfocus.com/bid/37092 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091124_00 http://www.vupen.com/english/advisories/2009/3328 https://exchange.xforce.ibmcloud.com/vulnerabilities/54415 https://kb.altiris.com/article.asp?article=50072&p=1 https://kb.altiris.com/article.asp?article=50279&p=1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-3031 – Symantec ConsoleUtilities - ActiveX Buffer Overflow
https://notcve.org/view.php?id=CVE-2009-3031
Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument. Desbordamiento de búfer basado en pila en el método BrowseAndSaveFile en el control ActiveX ConsoleUtilities v6.0.0.1846 en AeXNSConsoleUtilities.dll en Symantec Altiris Notification Server (NS) v6.0 anterior a R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution v6.9 SP3, y Symantec Management Platform (SMP) v7.0 anterior a SP3, permite a atacantes remotos ejecutar código de su elección a través de una cadena larga en el segundo argumento. • https://www.exploit-db.com/exploits/9853 https://www.exploit-db.com/exploits/16613 http://sotiriu.de/adv/NSOADV-2009-001.txt http://www.securityfocus.com/archive/1/507625/100/0/threaded http://www.securityfocus.com/bid/36698 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091102_00 http://www.vupen.com/english/advisories/2009/3117 https://kb.altiris.com/article.asp?article=49389&p=1 https://kb& • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-3179
https://notcve.org/view.php?id=CVE-2009-3179
Multiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown client-side attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.17, as identified by (1) "Symantec Altiris Deployment Solution 6.9 exploit, (2) "Symantec Altiris Deployment Solution 6.9 exploit (II)," and (3) "Symantec Altiris Deployment Solution 6.9 exploit (III)." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. Múltiples vulnerabilidades no especificadas en Symantec Altiris Deployment Solution v6.9, podrían permitir a atacantes remotos ejecutar código de su elección a través de vectores de ataque del lado del cliente, como se demostró por un módulo concreto en VulnDisco Pack Professional v7.17, como se identificó por (1) exploit "Symantec Altiris Deployment Solution v6.9, (2) exploit "Symantec Altiris Deployment Solution v6.9 (II)," y (3) exploit "Symantec Altiris Deployment Solution v6.9 (III)." NOTA, como en 20090909, de esta información no se tiene información de la acción. • http://intevydis.com/vd-list.shtml http://secunia.com/advisories/36587 http://www.securityfocus.com/bid/36247 •