pcAnywhere Pre-Authentication Buffer Overflow Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1015284
|
|
SecurityTracker URL: http://securitytracker.com/id?1015284
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Nov 30 2005
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Symantec Advisory
|
Version(s): 11.0.1 and prior versions, 11.5.1
|
Description: A vulnerability was reported in pcAnywhere. A remote user can cause denial of service conditions.
A remote user can trigger a buffer overflow and cause the pcAnywhere component to crash. pcAnywhere must be restarted to return
to normal operations.
The vendor credits Tal at See-Security technologies Ltd. with reporting this vulnerability.
|
Impact: A remote user can cause pcAnywhere to crash.
|
Solution: The vendor has issued a fix.
For consumer versions of Symantec pcAnywhere:
http://www.symantec.com/techsupp/files/pca/index.html
For
enterprise versions of Symantec pcAnywhere:
http://www.symantec.com/techsupp/enterprise/products/spca/files.html
The vendor's
advisory is available at:
http://securityresponse.symantec.com/avcenter/security/Content/2005.11.29.html
|
Vendor URL: securityresponse.symantec.com/avcenter/security/Content/2005.11.29.html (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 29 Nov 2005 20:09:12 -0500
Subject: Symantec pcAnywhere Denial of Service
|
http://securityresponse.symantec.com/avcenter/security/Content/2005.11.29.html
|
|