Friday, April 27, 2007 11:00 AM
cmosby
Symantec Products Information Disclosure and Buffer Overflow - Advisories - Secunia
Symantec Products Information Disclosure and Buffer Overflow
Secunia Advisory:
SA25013
Release Date:
2007-04-27
Critical:

Less critical
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
Local system
Solution Status:
Vendor Patch
Software:
Symantec Backup Exec System Recovery 6.x
Symantec LiveState Recovery 6.x
Symantec Norton Ghost 10.x
Symantec Norton Save & Recovery 11.x
Symantec Norton Save & Recovery for Norton System Works 2007 1.x
Symantec Norton Save & Recovery Sony Euro 1.x
Description:
A vulnerability and a security issue have been reported in various Symantec products, which can be exploited by malicious, local users to disclose sensitive information, cause a DoS (Denial of Service), and gain escalated privileges.
1) Scheduled backups to remote network shares save login credentials for remote shares in the application directory with insecure permissions (read access for everyone).
2) An unspecified error can be exploited to cause a buffer overflow, which can lead to a DoS or execution of arbitrary code with SYSTEM privileges.
The vulnerability and the security issue are reported in the following products and versions:
* Norton Ghost 10.0 and 10.01
* Norton Ghost for Norton System Works 10.0
* Norton Ghost for Dell 10.0
* Norton Save & Recovery 11.0, 11.01, and 11.01B
* Norton Save & Recovery for Norton System Works 2007 1.01B
* Norton Save & Recovery Sony Euro 1.01
* LiveState Recovery 6.0, 6.01, and 6.02
* BackupExec System Recovery 6.5, 6.52, 6.52A, and 6.53
Solution:
Update to the latest version via LiveUpdate.
Provided and/or discovered by:
The vendor credits Pravus and iDefense Labs.
Original Advisory:
http://securityresponse.symantec.com/avcenter/security/Content/2007.04.26.html
Source: Symantec Products Information Disclosure and Buffer Overflow - Advisories - Secunia
Filed under: Security and Anti-Virus, Patch Management