CVE-2005-0249
Summary
| CVE | CVE-2005-0249 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-02-08 05:00:00 UTC |
| Updated | 2019-09-20 13:24:00 UTC |
| Description | Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Antivirus Scan Engine | All | All | All | All |
| Application | Symantec | Antivirus Scan Engine | All | All | All | All |
| Application | Symantec | Brightmail Antispam | 4.0 | All | All | All |
| Application | Symantec | Brightmail Antispam | 5.5 | All | All | All |
| Application | Symantec | Brightmail Antispam | 4.0 | All | All | All |
| Application | Symantec | Brightmail Antispam | 5.5 | All | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.434 | mr3 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.437 | All | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.446 | mr4 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.457 | mr5 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.460 | mr6 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.464 | mr7 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.471 | mr8 | All | All |
| Application | Symantec | Client Security | 1.1.1_mr1_build_8.1.1.314a | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr2_build_8.1.1.319 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr3_build_8.1.1.323 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr4_build_8.1.1.329 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr5_build_8.1.1.336 | All | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.434 | mr3 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.437 | All | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.446 | mr4 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.457 | mr5 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.460 | mr6 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.464 | mr7 | All | All |
| Application | Symantec | Client Security | 1.0.1_build_8.01.471 | mr8 | All | All |
| Application | Symantec | Client Security | 1.1.1_mr1_build_8.1.1.314a | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr2_build_8.1.1.319 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr3_build_8.1.1.323 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr4_build_8.1.1.329 | All | All | All |
| Application | Symantec | Client Security | 1.1.1_mr5_build_8.1.1.336 | All | All | All |
| Application | Symantec | Gateway Security | 1.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0.1 | All | All | All |
| Application | Symantec | Gateway Security | 1.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0.1 | All | All | All |
| Application | Symantec | Mail Security | 4.0 | All | domino | All |
| Application | Symantec | Mail Security | 4.1 | build_458 | exchange | All |
| Application | Symantec | Mail Security | 4.1 | build_459 | exchange | All |
| Application | Symantec | Mail Security | 4.1 | build_461 | exchange | All |
| Application | Symantec | Mail Security | 4.5_build_719 | All | exchange | All |
| Application | Symantec | Mail Security | 4.0 | All | domino | All |
| Application | Symantec | Mail Security | 4.1 | build_458 | exchange | All |
| Application | Symantec | Mail Security | 4.1 | build_459 | exchange | All |
| Application | Symantec | Mail Security | 4.1 | build_461 | exchange | All |
| Application | Symantec | Mail Security | 4.5_build_719 | All | exchange | All |
| Application | Symantec | Norton Antivirus | 2.18_build_83 | All | exchange | All |
| Application | Symantec | Norton Antivirus | 2004 | All | windows | All |
| Application | Symantec | Norton Antivirus | 8.01.434 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.437 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.446 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.457 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.460 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.464 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.471 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.319 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.323 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.329 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1_build8.1.1.314a | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0 | All | macintosh_corporate | All |
| Application | Symantec | Norton Antivirus | 2.18_build_83 | All | exchange | All |
| Application | Symantec | Norton Antivirus | 2004 | All | windows | All |
| Application | Symantec | Norton Antivirus | 8.01.434 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.437 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.446 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.457 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.460 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.464 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.01.471 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.319 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.323 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1.329 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1.1_build8.1.1.314a | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0 | All | macintosh_corporate | All |
| Application | Symantec | Norton Internet Security | 2004 | All | professional | All |
| Application | Symantec | Norton Internet Security | 2004 | All | professional | All |
| Application | Symantec | Norton System Works | 2004 | All | windows | All |
| Application | Symantec | Norton System Works | 2004 | All | windows | All |
| Application | Symantec | Sav Filter Domino Nt Ports | build3.0.5 | All | aix | All |
| Application | Symantec | Sav Filter Domino Nt Ports | build3.0.5 | All | os_400 | All |
| Application | Symantec | Sav Filter Domino Nt Ports | build3.0.5 | All | aix | All |
| Application | Symantec | Sav Filter Domino Nt Ports | build3.0.5 | All | os_400 | All |
| Application | Symantec | Sav Filter For Domino Nt | 3.1.1 | All | All | All |
| Application | Symantec | Sav Filter For Domino Nt | 3.1.1 | All | All | All |
| Application | Symantec | Web Security | 3.01.59 | All | All | All |
| Application | Symantec | Web Security | 3.01.60 | All | All | All |
| Application | Symantec | Web Security | 3.01.61 | All | All | All |
| Application | Symantec | Web Security | 3.01.62 | All | All | All |
| Application | Symantec | Web Security | 3.01.63 | All | All | All |
| Application | Symantec | Web Security | 3.01.67 | All | All | All |
| Application | Symantec | Web Security | 3.01.68 | All | All | All |
| Application | Symantec | Web Security | 3.01.59 | All | All | All |
| Application | Symantec | Web Security | 3.01.60 | All | All | All |
| Application | Symantec | Web Security | 3.01.61 | All | All | All |
| Application | Symantec | Web Security | 3.01.62 | All | All | All |
| Application | Symantec | Web Security | 3.01.63 | All | All | All |
| Application | Symantec | Web Security | 3.01.67 | All | All | All |
| Application | Symantec | Web Security | 3.01.68 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Symantec Norton Anti-Virus Buffer Overflow in DEC2EXE in Parsing UPX Compressed Files Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | Third Party Advisory, VDB Entry |
| 20050208 Symantec AntiVirus Library Heap Overflow | ISS | xforce.iss.net | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry |
| 404 Not Found | CONFIRM | www.symantec.com | Patch, Vendor Advisory |
| US-CERT Vulnerability Note VU#107822 | CERT-VN | www.kb.cert.org | Patch, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.