Saturday, November 23, 2013

Symantec Management Platform Agent and Package Server Vulnerability

The Symantec Management Platform Symantec Management Agent and/or Package Server Agent Disk Space Check and Drive Overflow features can potentially cause the space of it's system drive to be fully consumed. When this occurs, no additional data can be written to the drive, such as security patches or antivirus definitions.

As an example, a system where the Package Server Agent is installed on drive D. The Package Server was assigned more packages than the D drive had space for. The only drive with enough space for the download was the system drive, drive C. This drive was promptly consumed of drive space. After this it was noticed that antivirus definitions for Thursday, November 21, 2013 are for Wednesday, November 20, 2013 r25, but a system having this issue is nearly a month old.


Drive Space Check will check whether there is free space available on the drive containing the Package Server Agent installation. The amount of free space on a drive must be, at least, the value of the Min Disk Free Space (Mbytes) registry key in addition to 120% of the download size. If there is enough drive space, it will download it to this drive. If there is not enough drive space, the Drive Overflow feature is implemented.

Drive Overflow will check whether a drive, other than the drive containing the Package Server Agent installation, has available disk space for the download. If space is available on the drive, a folder will be created using the Package Server Agent installation path, replacing the drive letter with the drive letter of the using a path as the  has the space and download there, if no other drive has this space then it will not download the package.

No comments:

Post a Comment