Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based automatic encryption, which might allow local users to read sensitive data via an unspecified decryption method.
Link | Tags |
---|---|
http://securitytracker.com/id?1016619 | vdb entry |
http://www.securityfocus.com/bid/19248 | vdb entry |
http://www.securityfocus.com/archive/1/441850/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28181 | vdb entry |
http://www.symantec.com/avcenter/security/Content/2006.08.01a.html | vendor advisory |
http://www.vupen.com/english/advisories/2006/3097 | vdb entry |
http://secunia.com/advisories/21280 | third party advisory |