Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Symantec LiveUpdate Client Local Information Disclosure Vulnerability

Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability.

Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file.

A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server.







 

Privacy Statement
Copyright 2008, SecurityFocus