Friday, April 27, 2007 11:00 AM cmosby

Symantec Products Information Disclosure and Buffer Overflow - Advisories - Secunia

 

Symantec Products Information Disclosure and Buffer Overflow
Advisory Available in Danish Advisory Available in German

Secunia Advisory:
SA25013

Release Date:
2007-04-27

Critical:

Less critical

Impact:
Exposure of sensitive information
Privilege escalation
DoS

Where:
Local system

Solution Status:
Vendor Patch

Software:
Symantec Backup Exec System Recovery 6.x
Symantec LiveState Recovery 6.x
Symantec Norton Ghost 10.x
Symantec Norton Save & Recovery 11.x
Symantec Norton Save & Recovery for Norton System Works 2007 1.x
Symantec Norton Save & Recovery Sony Euro 1.x

Description:
A vulnerability and a security issue have been reported in various Symantec products, which can be exploited by malicious, local users to disclose sensitive information, cause a DoS (Denial of Service), and gain escalated privileges.

1) Scheduled backups to remote network shares save login credentials for remote shares in the application directory with insecure permissions (read access for everyone).

2) An unspecified error can be exploited to cause a buffer overflow, which can lead to a DoS or execution of arbitrary code with SYSTEM privileges.

The vulnerability and the security issue are reported in the following products and versions:
* Norton Ghost 10.0 and 10.01
* Norton Ghost for Norton System Works 10.0
* Norton Ghost for Dell 10.0
* Norton Save & Recovery 11.0, 11.01, and 11.01B
* Norton Save & Recovery for Norton System Works 2007 1.01B
* Norton Save & Recovery Sony Euro 1.01
* LiveState Recovery 6.0, 6.01, and 6.02
* BackupExec System Recovery 6.5, 6.52, 6.52A, and 6.53

Solution:
Update to the latest version via LiveUpdate.

Provided and/or discovered by:
The vendor credits Pravus and iDefense Labs.

Original Advisory:
http://securityresponse.symantec.com/avcenter/security/Content/2007.04.26.html

Source: Symantec Products Information Disclosure and Buffer Overflow - Advisories - Secunia

Filed under: ,

Comments

No Comments