The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/194505 | third party advisory us government resource |
http://www.symantec.com/avcenter/security/Content/2009.01.15.html | patch vendor advisory |
http://www.securityfocus.com/bid/33247 | vdb entry |
http://securitytracker.com/id?1021609 | vdb entry |