First published: Fri Dec 31 2004(Updated: )
The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec PowerQuest DeployCenter | =5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2609 is classified as a high-severity vulnerability due to its potential for exposing sensitive information.
To fix CVE-2004-2609, update Symantec PowerQuest DeployCenter to a version that addresses this vulnerability.
The implications of CVE-2004-2609 include unauthorized access to unencrypted sensitive information, particularly Windows domain account passwords.
Users of Symantec PowerQuest DeployCenter version 5.5 are affected by CVE-2004-2609.
CVE-2004-2609 is considered a local vulnerability, meaning it requires local access to exploit.