Vulnerabilities > CVE-2005-2766 - Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1.1000/9.0.4

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
symantec

Summary

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.

Vulnerable Configurations

Part Description Count
Application
Symantec
2