Vulnerability Description
The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Appstream Client | 5.2 |
Related Weaknesses (CWE)
References
- http://securitytracker.com/id?1021609
- http://www.kb.cert.org/vuls/id/194505US Government Resource
- http://www.securityfocus.com/bid/33247
- http://www.symantec.com/avcenter/security/Content/2009.01.15.htmlPatchVendor Advisory
- http://securitytracker.com/id?1021609
- http://www.kb.cert.org/vuls/id/194505US Government Resource
- http://www.securityfocus.com/bid/33247
- http://www.symantec.com/avcenter/security/Content/2009.01.15.htmlPatchVendor Advisory
FAQ
What is CVE-2008-4388?
CVE-2008-4388 is a vulnerability with a CVSS score of 9.3 (HIGH). The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to exe...
How severe is CVE-2008-4388?
CVE-2008-4388 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4388?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Appstream Client.