1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Symantec Vulnerability Found In AV

Discussion in 'Security and Privacy' started by TeMerc, 2006/05/25.

  1. 2006/05/25
    TeMerc

    TeMerc Inactive Alumni Thread Starter

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Threat Chaos Blog
     
  2. 2006/05/25
    TeMerc

    TeMerc Inactive Alumni Thread Starter

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    From the above linked article:
     

  3. to hide this advert.

  4. 2006/05/25
    BOBBO

    BOBBO Geek Member

    Joined:
    2002/01/07
    Messages:
    1,892
    Likes Received:
    19
    That got me wondering if I was vulnerable. My desktop's NAV 2005 shows version 11.0.16.4, so it looks good. Then I checked the NAV 2004 on my wife's laptop, and it shows version 10.0.29.4. Not so good. Both are kept up to date, so here's hoping Symantec will plug the hole before trouble hits.
     
  5. 2006/05/26
    BOBBO

    BOBBO Geek Member

    Joined:
    2002/01/07
    Messages:
    1,892
    Likes Received:
    19
  6. 2006/05/26
    TeMerc

    TeMerc Inactive Alumni Thread Starter

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    SYM06-010
    May 25, 2006
    Symantec Client Security and Symantec AntiVirus Elevation of Privilege
    Revision History
    May 26, 2006 - Updated Products Affected section and other details

    Impact
    High
    Remote
    Yes
    Local
    Yes
    Authentication Required
    No
    Exploit publicly available
    No


    Overview
    A stack overflow in Symantec Client Security and Symantec AntiVirus Corporate Edition could potentially allow a remote or local attacker to execute code on the affected machine.

    Products Affected
    Product Version Build Solution
    Symantec Client Security 3.1 All Pending
    Symantec Antivirus Corporate Edition 10.1 All Pending


    Products Not Affected
    Norton Product line No products in the Norton product line are affected
    Details
    Symantec was notified that Symantec Client Security and Symantec AntiVirus Corporate Edition are susceptible to a potential stack overflow. Exploiting this overflow successfully could potentially cause a system crash, or allow a remote or local attacker to execute arbitrary code with System level rights on the affected system.

    Symantec Response
    This advisory will be updated when product updates to address this issue are available.

    Upgrade Information
    Symantec engineers have verified that this vulnerability exists in the product versions listed above. We are continuing to evaluate other versions of our software. This advisory will be updated when additional information is available.

    Symantec Advidsory

    Source: SANS
     
  7. 2006/05/27
    TeMerc

    TeMerc Inactive Alumni Thread Starter

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Handler's Diary May 27th 2006

    Symantec Patch Posted (NEW)
    Published: 2006-05-27,
    Last Updated: 2006-05-27 20:01:00 UTC by Deborah Hale (Version: 1)

    Symantec Patch

    SANS
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.