Command Injection Vulnerability in Symantec Security Information Manager
CVE-2006-3072

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
19 June 2006

Summary

The M4 Macro Library in Symantec Security Information Manager prior to the 4.0.2.29 HOTFIX 1 version is susceptible to a command injection vulnerability. Local users can exploit this weakness by crafting malicious 'rule definitions' that lead to the execution of arbitrary commands. This flaw generates unsafe Java code during the M4 transformation process, which can be leveraged to perform unauthorized operations within the system, potentially compromising security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.