Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.
Link | Tags |
---|---|
http://securitytracker.com/id?1016534 | vdb entry |
http://www.securityfocus.com/archive/1/440448/100/0/threaded | mailing list |
http://www.digitalbullets.org/?p=3 | |
http://securityreason.com/securityalert/1261 | third party advisory |