5

CVE-2012-0291

Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) allow remote attackers to cause a denial of service (application crash or hang) via (1) malformed data from a client, (2) malformed data from a server, or (3) an invalid response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Pcanywhere Update sp3 Version <= 12.5
Symantec ≫ Pcanywhere Version 10.0
Symantec ≫ Pcanywhere Version 10.5
Symantec ≫ Pcanywhere Version 11.0
Symantec ≫ Pcanywhere Version 11.0.1
Symantec ≫ Pcanywhere Version 11.5
Symantec ≫ Pcanywhere Version 11.5.1
Symantec ≫ Pcanywhere Version 12.0
Symantec ≫ Pcanywhere Version 12.0.1
Symantec ≫ Pcanywhere Version 12.0.2
Symantec ≫ Pcanywhere Version 12.0.3
Symantec ≫ Pcanywhere Version 12.1
Symantec ≫ Pcanywhere Version 12.5
Symantec ≫ Pcanywhere Version 12.5 Update sp1
Symantec ≫ Pcanywhere Version 12.5 Update sp2
Symantec ≫ Pcanywhere Version 12.5.3
Symantec ≫ Pcanywhere Version 12.5.265
Symantec ≫ Pcanywhere Version 12.5.539
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.58% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/48092
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120124_00
Vendor Advisory
http://www.securityfocus.com/bid/51965