CVE-2009-1432

Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.
References
Link Resource
http://secunia.com/advisories/34856 Third Party Advisory
http://secunia.com/advisories/34935 Third Party Advisory
http://securitytracker.com/id?1022136 Third Party Advisory VDB Entry
http://securitytracker.com/id?1022137 Third Party Advisory VDB Entry
http://securitytracker.com/id?1022138 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/34668 Third Party Advisory VDB Entry
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1202 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1204 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 Third Party Advisory VDB Entry
http://secunia.com/advisories/34856 Third Party Advisory
http://secunia.com/advisories/34935 Third Party Advisory
http://securitytracker.com/id?1022136 Third Party Advisory VDB Entry
http://securitytracker.com/id?1022137 Third Party Advisory VDB Entry
http://securitytracker.com/id?1022138 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/34668 Third Party Advisory VDB Entry
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00 Vendor Advisory
http://www.vupen.com/english/advisories/2009/1202 Third Party Advisory
http://www.vupen.com/english/advisories/2009/1204 Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:antivirus:10.1:-:*:*:corporate:*:*:*
cpe:2.3:a:symantec:antivirus:10.1:maintenance_release7:*:*:corporate:*:*:*
cpe:2.3:a:symantec:antivirus:10.2:-:*:*:corporate:*:*:*
cpe:2.3:a:symantec:antivirus:10.2:maintenance_release1:*:*:corporate:*:*:*
cpe:2.3:a:symantec:client_security:3.1:-:*:*:*:*:*:*
cpe:2.3:a:symantec:client_security:3.1:maintenance_release7:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:-:*:*:*:*:*:*
cpe:2.3:a:symantec:endpoint_protection:11.0:maintenance_release1:*:*:*:*:*:*

History

21 Nov 2024, 01:02

Type Values Removed Values Added
References () http://secunia.com/advisories/34856 - Third Party Advisory () http://secunia.com/advisories/34856 - Third Party Advisory
References () http://secunia.com/advisories/34935 - Third Party Advisory () http://secunia.com/advisories/34935 - Third Party Advisory
References () http://securitytracker.com/id?1022136 - Third Party Advisory, VDB Entry () http://securitytracker.com/id?1022136 - Third Party Advisory, VDB Entry
References () http://securitytracker.com/id?1022137 - Third Party Advisory, VDB Entry () http://securitytracker.com/id?1022137 - Third Party Advisory, VDB Entry
References () http://securitytracker.com/id?1022138 - Third Party Advisory, VDB Entry () http://securitytracker.com/id?1022138 - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/34668 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/34668 - Third Party Advisory, VDB Entry
References () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00 - Vendor Advisory () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090428_00 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2009/1202 - Third Party Advisory () http://www.vupen.com/english/advisories/2009/1202 - Third Party Advisory
References () http://www.vupen.com/english/advisories/2009/1204 - Third Party Advisory () http://www.vupen.com/english/advisories/2009/1204 - Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/50172 - Third Party Advisory, VDB Entry

Information

Published : 2009-04-30 20:30

Updated : 2024-11-21 01:02


NVD link : CVE-2009-1432

Mitre link : CVE-2009-1432

CVE.ORG link : CVE-2009-1432


JSON object : View

Products Affected

symantec

  • endpoint_protection
  • antivirus
  • client_security
CWE
CWE-20

Improper Input Validation