CVE-2008-1754: Low severity symantec deployment solution vulnerability
Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1754?
CVE-2008-1754 is considered a medium severity vulnerability due to the potential for local users to access sensitive information.
How do I fix CVE-2008-1754?
To fix CVE-2008-1754, upgrade to Symantec Altiris Deployment Solution version 6.9.164 or later, which addresses the issue.
What type of vulnerability is CVE-2008-1754?
CVE-2008-1754 is a local information disclosure vulnerability due to the storage of passwords in cleartext in memory.
Which versions of Symantec Altiris Deployment Solution are affected by CVE-2008-1754?
CVE-2008-1754 affects versions 6.8, 6.8-SP1, and 6.8.380 of Symantec Altiris Deployment Solution.
What can attackers achieve by exploiting CVE-2008-1754?
Attackers can obtain sensitive Deployment Solution Agent passwords by dumping the memory of the AClient.exe process.