Symantec Data Loss Prevention KeyView Filter Memory Corruption Errors Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1024263 |
|
SecurityTracker URL: http://securitytracker.com/id?1024263
|
|
CVE Reference:
CVE-2010-0126, CVE-2010-0131, CVE-2010-0133, CVE-2010-0134, CVE-2010-0135, CVE-2010-1524, CVE-2010-1525
(Links to External Site)
|
Date: Jul 29 2010
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 8.1.1, 9.x, 10.0, 10.5
|
Description:
Several vulnerabilities were reported in Symantec Data Loss Prevention. A remote user can cause denial of service conditions on the target system.
A remote user can create a specially crafted file that, when processed by the target application, will trigger a memory corruption error and cause the child process to crash.
Symantec Data Loss Prevention Enforce/Detection Servers for Windows, Symantec Data Loss Prevention Enforce/Detection Servers for Linux, and Symantec Data Loss Prevention Endpoint Agents are affected.
Carsten Eiram and Dyon Balding of Secunia Research reported these vulnerabilities.
|
Impact:
A remote user can create a file that, when processed by the target application, will cause the resulting child process to crash.
|
Solution:
The vendor has issued a fix (10.5.1 ReleaseUpdate).
The vendor's advisory is available at:
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01
|
Vendor URL: www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01 (Links to External Site)
|
Cause:
Access control error, Boundary error
|
Underlying OS:
Linux (Red Hat Enterprise), Windows (2003), Windows (Vista), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 29 Jul 2010 03:32:17 +0000
Subject: Symantec Data Loss Prevention
|
Security Advisories Relating to Symantec Products - Multi-Vendor Autonomy KeyView Filter Multiple Security Issues
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100727_01
CVE-2010-0126
CVE-2010-0131
CVE-2010-0133
CVE-2010-0134
CVE-2010-0135
CVE-2010-1524
CVE-2010-1525
|
|