Symantec Ghost Solution Suite UDP Packet Multiple Denial of Service Vulnerabilities
TITLE: Symantec Ghost Solution Suite UDP Packet Multiple Denial of Service Vulnerabilities
CLASS: Failure to Handle Exceptional Conditions
CVE:
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 05 2007 12:00AM
UPDATE: Jun 06 2007 04:40PM
CREDIT: Pravus is credited with discovering these issues.
VULNERABLE:
Symantec Ghost Solutions Suite (SGSS) 1.1NOT VULNERABLE:
Symantec Ghost Solutions Suite (SGSS) 1.0
Symantec Ghost Solution Suite (SGSS) 2.0
Vai alla pagina originale su Security Focus
Discussion
Symantec Ghost Solution Suite is prone to multiple denial-of-service vulnerabilities because it fails to handle a certain UDP network packet.
Successful exploits may allow remote attackers to cause denial-of-service conditions via the client or server daemons.
These issues affects versions 2.0.0 and prior.
Exploit
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.
Solution
Solution:
The vendor released an advisory and fixes to address these issues. Please see the references more information.
Symantec Ghost Solutions Suite (SGSS) 1.1
- Symantec GSS1.1.b1341.Update.CH.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.CH.exe - Symantec GSS1.1.b1341.Update.DE.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.DE.exe - Symantec GSS1.1.b1341.Update.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.exe - Symantec GSS1.1.b1341.Update.FR.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.FR.exe - Symantec GSS1.1.b1341.Update.JP.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.JP.exe - Symantec GSS1.1.b1341.Update.KN.exe
http://www.symantec.com/avcenter/security/GSS/GSS1.1.b1341.Update.KN.exe
References
References:
- SYM07-013: Multiple Symantec Ghost Solution Suite Vulnerabilities (Symantec)
- Symantec Homepage (Symantec)
- iDefense Security Advisory 06.05.07: Symantec Ghost Multiple Denial of Service (iDefense Labs)
- iDefense Security Advisory 06.05.07: Symantec Ghost Multiple Denial of Service (iDefense Labs)