CVE-2008-0640 Information

Description

Symantec Ghost Solution Suite 1.1 before 1.1 patch 2 2.0.0 and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.

Reference

http://secunia.com/advisories/28853 http://www.securityfocus.com/bid/27644 http://www.securitytracker.com/id?1019356 http://www.symantec.com/avcenter/security/Content/2008.02.07.html http://www.vupen.com/english/advisories/2008/0474

Share on: