First published: Wed Mar 18 2009(Updated: )
Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec pcAnywhere | =12.1 | |
Symantec pcAnywhere | =11.5 | |
Symantec pcAnywhere | <=12.5 | |
Symantec pcAnywhere | =10.0 | |
Symantec pcAnywhere | =11.0.1 | |
Symantec pcAnywhere | =12.0 | |
Symantec pcAnywhere | =11.5.1 | |
Symantec pcAnywhere | =11.0 | |
Symantec pcAnywhere | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0538 is rated as a medium severity vulnerability due to its potential for unauthorized memory access and application crashes.
To fix CVE-2009-0538, update Symantec pcAnywhere to version 12.5 SP1 or later as it contains the patch for this vulnerability.
Versions of Symantec pcAnywhere prior to 12.5 SP1, including 10.0, 11.0, 11.5, and 12.0, are affected by CVE-2009-0538.
CVE-2009-0538 can enable attacks that lead to reading or modifying arbitrary memory locations, causing application crashes or possible denial of service.
Local users of affected versions of Symantec pcAnywhere may be impacted by CVE-2009-0538.