vendor:
pcAnywhere
by:
David Maciejak
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: pcAnywhere
Affected Version From: 11
Affected Version To: 11.5.2001
Patch Exists: YES
Related CWE: N/A
CPE: a:symantec:pcanywhere
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2006
pcAnywhere Authentication Denial of Service Vulnerability
pcAnywhere is vulnerable to a buffer overflow vulnerability. Because the flaw can be triggered prior to authentication, the vulnerability is exploitable by remote attackers without valid credentials. It is confirmed that the vulnerability can be exploited to cause a denial of service. Supported versions 11.0.1 and 11.5.1 are confirmed affected. Previous versions are vulnerable and users are advised to upgrade to the latest supported version.
Mitigation:
Upgrade to the latest supported version of pcAnywhere.