CVE-2007-3874
iDEFENSE Security Advisory 2007-10-31.2
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote attackers to read arbitrary files via unspecified vectors.
Vulnerabilidad de salto de directorio en el demonio tftp/mftp en el componente del servidor PXE (pxemtftp.exe) en Symantec Altiris Deployment Solution 6.x anterior a 6.8.380.0 permite a atacantes remotos leer archivos de su elección a través de vectores no especificados.
Remote exploitation of a directory traversal vulnerability in Symantec's Altiris Deployment Solution products could allow attackers to gain read access to arbitrary files hosted on the Altiris server. iDefense confirmed the existence of this vulnerability in Altiris Deployment Solution for Windows version 6.8. The specific vulnerable executable is pxemtftp.exe version 6.8.8297.48.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-07-18 CVE Reserved
- 2007-10-31 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=619 | Third Party Advisory | |
http://www.securityfocus.com/bid/26266 | Vdb Entry | |
http://www.securitytracker.com/id?1018875 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3673 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38178 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.symantec.com/avcenter/security/Content/2007.10.31.html | 2017-07-29 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27412 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Altiris Search vendor "Altiris" | Deployment Solution Search vendor "Altiris" for product "Deployment Solution" | 6.0 Search vendor "Altiris" for product "Deployment Solution" and version "6.0" | - |
Affected
| ||||||
Altiris Search vendor "Altiris" | Deployment Solution Search vendor "Altiris" for product "Deployment Solution" | 6.8 Search vendor "Altiris" for product "Deployment Solution" and version "6.8" | - |
Affected
| ||||||
Altiris Search vendor "Altiris" | Deployment Solution Search vendor "Altiris" for product "Deployment Solution" | 6.8 Search vendor "Altiris" for product "Deployment Solution" and version "6.8" | sp1 |
Affected
| ||||||
Altiris Search vendor "Altiris" | Deployment Solution Search vendor "Altiris" for product "Deployment Solution" | 6.8 Search vendor "Altiris" for product "Deployment Solution" and version "6.8" | sp2 |
Affected
|