T-015: InstallShield / Macrovision / Acresso FLEXnet Connect Vulnerabilities


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) T-015: InstallShield / Macrovision / Acresso FLEXnet Connect Vulnerabilities
# 1  
Old 11-13-2008
T-015: InstallShield / Macrovision / Acresso FLEXnet Connect Vulnerabilities

Acresso FLEXnet Connect executes scripts that are insecurely retrieved from a remote web server, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. The risk is MEDIUM. By modifying the rule script that is sent to a FLEXnet Connect client, a remote unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

2 More Discussions You Might Find Interesting

1. HP-UX

installshield....

hi all is it possible to automate installaion process of any software on unix? for eg. we have our front end on windows and we have installshield package that installs everything creating folder structure to creating database. now we are planning to automate our backend installation like... (0 Replies)
Discussion started by: zedex
0 Replies

2. Solaris

some questions on 310-015

hi can any1 pls ans these questions 22. Which two statements about the functionality of the syslogd daemon are true? (Choose two) A. Error messages can only be logged locally in a system log. B. The kernel, daemons, and syslogd each write directly to a system log. C. Syslogd can write... (1 Reply)
Discussion started by: azeem_3001
1 Replies
Login or Register to Ask a Question
DNLOGIN(1)						      General Commands Manual							DNLOGIN(1)

NAME
dnlogin - Connect as a terminal to a DECnet system SYNOPSIS
dnlogin [options] nodename Options: [-Vh] [-d level] [-e char] DESCRIPTION
dnlogin connects to a remote DECnet system. This application implements the CTERM protocol over DECnet for connecting to a remote DECnet host. It expects to be run from a VT100-com- patible terminal. dnlogin is a replacement for the old "sethost" program. OPTIONS
-e <char> Set the exit character. By default this is ^]. You can specify the exit character as a control character by preceding it with a cir- cumflex eg (^A means control-A) or as a number in decimal (default), octal (starting with a zero), or hexadecimal (preceded by 0x or 0X). -T connect timeout Specifies the maximum amount of time the command will wait to establish a connection with the remote node. a 0 here will cause it to wait forever. The default is 60 seconds -h -? Displays help for using the command. -V Show the version of the package that dnlogin was built with. EXAMPLES
Connect to remote VAX host named "mv3100". dnlogin mv3100 HELPFUL HINTS
The CTERM specifications available from Digital does not include how to setup VMS terminal characteristics, so the host cannot identify the capabilities of the session we are creating. The simplest workaround is to set the terminal capabilities manually upon login or including the following command in the login.com DCL procedure. $ SET TERM/DEC_CRT SEE ALSO
dntype(1), dndir(1), dndel(1), dntask(1), dnping(1) DECnet utilities October 21 2005 DNLOGIN(1)