AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2004-10/0211.html - Vendor Advisory | |
References | () http://archives.neohapsis.com/archives/bugtraq/2004-10/0266.html - | |
References | () http://packetstorm.linuxsecurity.com/0410-advisories/index2.html - | |
References | () http://secunia.com/advisories/12944 - Vendor Advisory | |
References | () http://securitytracker.com/id?1011862 - Vendor Advisory | |
References | () http://www.altiris.com/support/forum/Framesearch.aspx?vpath=/aexkb/public%20articles/6.x/deployment%20solution/kb/ds%20client%20security%20kb%20article%2010-22-04.doc&art=AKB6859&source=Altiris%20Helpdesk&artID=23644&refpara=532392&key=akb6859 - | |
References | () http://www.osvdb.org/11031 - | |
References | () http://www.securityfocus.com/bid/11498 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17814 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2622
Mitre link : CVE-2004-2622
CVE.ORG link : CVE-2004-2622
JSON object : View
Products Affected
altiris
- deployment_server_extension_for_ibm_director
CWE