Symantec releases patch for application delivery program
Symantec and the U.S. Computer Emergency Readiness Team are warning about a serious vulnerability within the company's AppStream product, used for steaming applications from a central server to thin-client desktops, though a patch has been released.
The product affected is AppStream version 5.2, which is part of the Symantec Endpoint Virtualization Suite formerly known as Software Virtualization Solution (SVS) Pro.
The problem lies in the LaunchObj ActiveX control, which fails to validate external input when called on by an unauthorized server. CERT wrote in a brief advisory on Friday that if a user can be convinced into viewing a specially crafted HTML (Hypertext Markup Language) document, a hacker could execute arbitrary code with the privileges of that user.
Symantec has created an update to fix the problem and advised administrators to apply it.
Both Symantec and CERT discovered the flaw, which Symantec rated as "high" severity. However, it appears that no exploits have been publicly released.
Symantec acquired AppStream in April 2008. Symantec had sold the AppStream software since 2006.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
symantec
Powered by TwitterOn Twitter now
symantec
Brian Proffitt
SourceForge Balances Between Community, Lawmakers
Tom Henderson
Top Ten General Operating Systems Rants
pasmith
Gaming: New DRM to combat piracy, drive away customers
Christopher Dawson
Google privacy woes: Can they be our cloud provider of choice?
Esther Schindler
Drupal's Dries Buytaert on Building the Next Drupal
sjvn
Who's really to blame for the Windows XP Patch BSOD?
claird
Web developers: There's no excuse for device incompatibility

19 Weird but Real Gadgets and Gizmos
Take a walk on tech's wild side with some of the strangest, most original, and most bizarre gadgets you've ever seen. We've got vacuums for your lawn, swimwear that can charge your iPod, and grenades that don't explode but still go boom. View slideshow.
See also:






