SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#221257

Symantec AppStream and Workspace Streaming vulnerable to arbitrary code download and execution

Overview

The Symantec AppStream and Workspace Streaming clients fail to properly validate downloads, which can allow a remote, unauthenticated attacker to download and execute arbitrary code on a vulnerable system.

I. Description

Symantec Workspace Streaming is a software distribution solution that "streams" applications to client desktops. Older versions of the software are known as AppStream or Altiris Streaming System. The Symantec Workspace Streaming client is configured to handle the aswe protocol. By processing an aswe:// URI, the Symantec Workspace Streaming client will download and execute applications from the specified Workspace Streaming server. The Symantec Workspace Streaming client and prior variants fail to properly authenticate with the server component of the software.

II. Impact

By convincing a user to view a specially crafted HTML document (e.g., a webpage or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. Other mechanisms for accessing the Workspace Streaming Client, e.g., via the aswe protocol handler, can have the same impact.

III. Solution

Apply an update

This issue is addressed in Symantec Workspace Streaming 6.1 SP4. Please see Symantec Advisory SYM10-008 for more details.

Vendor Information

VendorStatusDate NotifiedDate Updated
Symantec, Inc.Affected2008-10-172010-06-17

References

http://www.cert.org/tech_tips/securing_browser/
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100616_00
https://fileconnect.symantec.com/
http://www.securityfocus.com/bid/40611
http://secunia.com/advisories/40233/

Credit

This vulnerability was reported by Will Dormann of the CERT/CC.

This document was written by Will Dormann.

Other Information

Date Public:2010-06-16
Date First Published:2010-06-17
Date Last Updated:2010-06-18
CERT Advisory: 
CVE-ID(s):CVE-2008-4389
NVD-ID(s):CVE-2008-4389
US-CERT Technical Alerts: 
Metric:8.02
Document Revision:13

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2010 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader