In association with heise online

16 May 2007, 15:33

Vulnerability in Symantec's Discovery

Security experts from Secunia have discovered vulnerabilities in Symantec Discovery, a network inventory package. This enables attackers to inject malicious code into affected systems using manipulated network packets. The software affected is a solution purchased from Centennial, in whose product the problem also exists.

During the processing of network packets in the service CentennialIPTransferServer (XFERWAN.EXE) a buffer overflow can occur due to a faulty length check. The service analyzes strings in TCP packets. By using carefully crafted strings, attackers can inject code from the local Net, which is then executed with system rights.

Centennial has already released an update on their website which is available for downloading for registered customers. Symantec is still working on an update. Administrators should refrain from using the service until the update has been made available. The vulnerability also affects the Numara Asset Manager, for which no there is no available update either.

See also:

(mba)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit