CVE-2004-0445
Summary
| CVE | CVE-2004-0445 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-07-07 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:N/AC:H/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:H/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Client Firewall | 5.01 | All | All | All |
| Application | Symantec | Client Firewall | 5.1.1 | All | All | All |
| Application | Symantec | Client Security | 1.0 | All | All | All |
| Application | Symantec | Client Security | 1.1 | All | All | All |
| Application | Symantec | Client Security | 1.2 | All | All | All |
| Application | Symantec | Client Security | 1.3 | All | All | All |
| Application | Symantec | Client Security | 1.4 | All | All | All |
| Application | Symantec | Client Security | 1.5 | All | All | All |
| Application | Symantec | Client Security | 1.6 | All | All | All |
| Application | Symantec | Client Security | 1.7 | All | All | All |
| Application | Symantec | Client Security | 1.8 | All | All | All |
| Application | Symantec | Client Security | 1.9 | All | All | All |
| Application | Symantec | Client Security | 2.0 | All | All | All |
| Application | Symantec | Norton Antispam | 2004 | All | All | All |
| Application | Symantec | Norton Internet Security | 2002 | All | All | All |
| Application | Symantec | Norton Internet Security | 2002 | All | pro | All |
| Application | Symantec | Norton Internet Security | 2003 | All | All | All |
| Application | Symantec | Norton Internet Security | 2003 | All | pro | All |
| Application | Symantec | Norton Internet Security | 2004 | All | All | All |
| Application | Symantec | Norton Internet Security | 2004 | All | pro | All |
| Application | Symantec | Norton Personal Firewall | 2002 | All | All | All |
| Application | Symantec | Norton Personal Firewall | 2003 | All | All | All |
| Application | Symantec | Norton Personal Firewall | 2004 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Secunia - Advisories - Symantec Client Firewall Products Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Norton AntiSpam SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [Full-Disclosure] EEYE: Symantec Multiple Firewall DNS Response Denial-of-Service | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Symantec Client Firewall SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#682110 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| www.osvdb.org/6100 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Symantec Client Firewall Remote Access and Denial of Service Issues | af854a3a-2127-422b-91ae-364da2661108 | securityresponse.symantec.com | Patch, Vendor Advisory |
| Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| O-141: Symantec Client Firewall Remote Access Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| Symantec Client Security SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.