CVE-2009-0538: Medium severity Symantec pcAnywhere vulnerability
Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0538?
CVE-2009-0538 is rated as a medium severity vulnerability due to its potential for unauthorized memory access and application crashes.
How do I fix CVE-2009-0538?
To fix CVE-2009-0538, update Symantec pcAnywhere to version 12.5 SP1 or later as it contains the patch for this vulnerability.
Which versions of Symantec pcAnywhere are affected by CVE-2009-0538?
Versions of Symantec pcAnywhere prior to 12.5 SP1, including 10.0, 11.0, 11.5, and 12.0, are affected by CVE-2009-0538.
What types of attacks can CVE-2009-0538 enable?
CVE-2009-0538 can enable attacks that lead to reading or modifying arbitrary memory locations, causing application crashes or possible denial of service.
Who is impacted by CVE-2009-0538?
Local users of affected versions of Symantec pcAnywhere may be impacted by CVE-2009-0538.