« Volver al listado

CVE-2009-0538

Estado: ModificadaMedia (4.6)—

Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0538",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-03-18T15:30:00.453",
  "references": [
    {
      "url": "http://osvdb.org/52797",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34305",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1021855",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.layereddefense.com/pcanywhere17mar.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/501930/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/33845",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0755",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49291",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/52797",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34305",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1021855",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.layereddefense.com/pcanywhere17mar.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/501930/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/33845",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0755",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49291",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-134"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file)."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de formato de cadena en Symantec pcAnywhere antes de 12.5 SP1 permite a atacantes remotos leer y modificar localizaciones de memoria de su elección y producir una denegación de servicio (caída de la aplicación) o posiblemente tener otro efecto no especificado mediante especificadores de cadena de formato en el nombre de ruta de fichero de un fichero de control remoto (alias fichero .CHF)."
    }
  ],
  "lastModified": "2026-06-16T23:05:15.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B5D2349-8330-4DE8-8040-6FDD368EFD32",
              "versionEndIncluding": "12.5"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DAB70F5-1B1B-426B-A1F9-6D91D0A160B2"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:10.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F0A6A97-1EFF-41C0-AAAA-B357C4C801F4"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "014AA70B-942F-4ADE-9EEF-4F5204438268"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:11.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0BF0A19-0AAD-44B2-9B51-85A985CC40A4"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:11.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A496D973-4BC8-4377-8C84-8F2CB281AEE1"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:11.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FF752E6-45B4-4D6D-90F8-AA69DB5C2775"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B13E1710-1723-4A52-ACDC-7FC511467152"
            },
            {
              "criteria": "cpe:2.3:a:symantec:pcanywhere:12.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECE0E3DD-23F9-4ACD-BF9D-986CE5232D4E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}