[NT] Symantec Enterprise Security Manager DoS



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Symantec Enterprise Security Manager DoS
------------------------------------------------------------------------


SUMMARY

The Symantec Enterprise Security Manager (ESM) platform and agent are
susceptible to a race condition that can cause the application to lock up,
resulting in a denial-of-service.

DETAILS

Vulnerable Systems:
* Symantec Enterprise Security Manager Platform versions 6 and 6.5.x
* Symantec Enterprise Security Manager Agent versions 6 and 6.5.x

A specially crafted invalid request can be sent to the manager server to
simulate an ESM agent. This causes both the ESM manager and ESM agent to
lock up, resulting in a denial-of-service. This issue affects all versions
of ESM managers and agents. Manager and agent restarts are required to
recover from an attack.

Resolution:
Symantec has released downloadable automated and manual fixes for most
supported ESM managers and agents. Complete instructions for automatically
updating ESM agents and manually updating ESM managers and agents can be
downloaded at the following site:
<http://www.symantec.com/avcenter/security/Content/2006.08.21a.html>
http://www.symantec.com/avcenter/security/Content/2006.08.21a.html


ADDITIONAL INFORMATION

The information has been provided by Anthony Bettini of McAfee Avert Labs.



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages