First published: Fri Apr 11 2008(Updated: )
Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Deployment Solutions | <=6.8 | |
Broadcom Symantec Deployment Solutions | =6.8-sp1 | |
Broadcom Symantec Deployment Solutions | =6.8.380 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1754 is considered a medium severity vulnerability due to the potential for local users to access sensitive information.
To fix CVE-2008-1754, upgrade to Symantec Altiris Deployment Solution version 6.9.164 or later, which addresses the issue.
CVE-2008-1754 is a local information disclosure vulnerability due to the storage of passwords in cleartext in memory.
CVE-2008-1754 affects versions 6.8, 6.8-SP1, and 6.8.380 of Symantec Altiris Deployment Solution.
Attackers can obtain sensitive Deployment Solution Agent passwords by dumping the memory of the AClient.exe process.