CVE-2009-3110: Race Condition
Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3110?
CVE-2009-3110 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2009-3110?
To fix CVE-2009-3110, upgrade to Symantec Altiris Deployment Solution version 6.9 SP3 Build 430 or later.
What are the potential impacts of exploiting CVE-2009-3110?
Exploiting CVE-2009-3110 allows remote attackers to read sensitive files and disrupt client updates.
Which versions of Symantec Altiris Deployment Solution are affected by CVE-2009-3110?
CVE-2009-3110 affects versions 6.9, 6.9 SP1, 6.9.164, 6.9.176, and 6.9.355 prior to SP3 Build 430.
Are there any workarounds for CVE-2009-3110 before applying the fix?
Temporary workarounds for CVE-2009-3110 may include restricting access to the file transfer port to trusted sources.