CVE-2008-6828: High severity symantec deployment solution vulnerability
Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6828?
CVE-2008-6828 is considered a moderate to high severity vulnerability due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2008-6828?
To fix CVE-2008-6828, upgrade to Symantec Altiris Deployment Solution version 6.9.355 SP1 or later.
What systems are affected by CVE-2008-6828?
CVE-2008-6828 affects versions of Symantec Altiris Deployment Solution prior to 6.9.355 SP1 and includes specific vulnerable versions such as 6.0 to 6.9.355.
What type of vulnerability is CVE-2008-6828?
CVE-2008-6828 is a local privilege escalation vulnerability caused by storing sensitive passwords in cleartext in memory.
Can local users exploit CVE-2008-6828?
Yes, local users can exploit CVE-2008-6828 to gain unauthorized privileges and potentially modify settings on Deployment Solution Server.