The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four stuffit /f:stuffit.dat invocations, possibly due to a buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Powerquest_deploycenter | Symantec | 5.5 (including) | 5.5 (including) |