Looking for:
Symantec pcanywhere 12.5 sp1 freeSymantec pcanywhere 12.5 sp1 free
File inclusion. Gain privilege. Sql injection. Cross site scripting. Directory traversal. Memory corruption. Http response splitting. Bypass something. Gain information.
Denial of service. Symantec pcAnywhere This process listens on TCP port Authentication is not required to exploit this vulnerability. The flaw exists within the awhost32 component which is used when handling incoming connections. When handling an authentication request the process copies the user supplied username unsafely to a fixed-length buffer of size 0x The vulnerability is due to improper bounds checking when copying user-supplied parameters into a fixed-length static buffer of size 0x A remote attacker can exploit this issue by sending a specially crafted authentication request to an affected application.
Successful exploitation would allow an attacker to execute arbitrary code on the target system. When handling an authentication request, the process copies the user supplied username unsafely to a fixed-length buffer of size 0x This can create an acess violation resulting in the remote session being dropped but leaving the client session open in specific instances.
It is possible to run arbitrary code on a targeted system in the context of the application which is normally System. Symantec pcAnywhere is also susceptible to access violation and input instability issues that could potentially prevent fully closing a remote client connection or result in a server or client denial of service.
This can generate an access violation resulting in the remote session being dropped but leaving the client session open in specific instances. This could potentially enable an unauthorized connection to the client session.
A manual restart of the Symantec pcAnywhere service would be required. Product updates are available to address these issues. Symantec engineers continue to review all functionality to further enhance the overall security of Symantec pcAnywhere.
Updates will be identified in revisions to this advisory as required. If Symantec pcAnywhere is installed but not required, it can be uninstalled from the system. Signatures are available through normal Symantec updates. Clarification for pcAnywhere versions prior to While older versions of pcAnywhere are affected. They are no longer supported. Users are strongly advised to upgrade to the latest release.
No comments:
Post a Comment