|
Symantec LiveUpdate Client Local Information Disclosure Vulnerability
Symantec LiveUpdate Client is susceptible to a local information disclosure vulnerability. Sensitive information such as the server name, IP address, subnet, subnet mask, connection protocol, username and password to access the LiveUpdate server are logged in a plain text file. A local attacker can subsequently access the file and disclose authentication credentials to access the server. This may lead to various attacks including the potential compromise of the server. |
|
|
Privacy Statement |