First published: Sat Aug 05 2006(Updated: )
Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based automatic encryption, which might allow local users to read sensitive data via an unspecified decryption method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec On-Demand Protection | <=2.6_build_2232 | |
Symantec On-Demand Agent | <=2.5_mr2_build_2156 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3457 has a medium severity due to improper encryption of sensitive data.
To fix CVE-2006-3457, update Symantec On-Demand Agent to version 2.5 MR2 Build 2157 or later, and Symantec On-Demand Protection to version 2.6 Build 2233 or later.
CVE-2006-3457 affects Symantec On-Demand Agent versions prior to 2.5 MR2 Build 2157 and Symantec On-Demand Protection versions prior to 2.6 Build 2233.
Yes, local users can exploit CVE-2006-3457 to read sensitive data due to improper file encryption.
Yes, CVE-2006-3457 is a known vulnerability that has been documented and addressed by security updates.