CVE-2005-2758
Summary
| CVE | CVE-2005-2758 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-05 19:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Antivirus Scan Engine | 4.0 | All | All | All |
| Application | Symantec | Antivirus Scan Engine | 4.0 | All | bluecoat | All |
| Application | Symantec | Antivirus Scan Engine | 4.0 | All | clearswift | All |
| Application | Symantec | Antivirus Scan Engine | 4.0 | All | netapp_filer | All |
| Application | Symantec | Antivirus Scan Engine | 4.0 | All | netapp_netcache | All |
| Application | Symantec | Antivirus Scan Engine | 4.3 | All | All | All |
| Application | Symantec | Antivirus Scan Engine | 4.3 | All | caching | All |
| Application | Symantec | Antivirus Scan Engine | 4.3 | All | clearswift | All |
| Application | Symantec | Antivirus Scan Engine | 4.3 | All | microsoft_sharepoint | All |
| Application | Symantec | Antivirus Scan Engine For Network Attached Storage | 4.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Accenture | Let there be change | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Symantec Anti Virus Scan Engine Buffer Overflow in Web Service Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#849209 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| www.osvdb.org/19854 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Symantec AntiVirus Scan Engine Web Service Administrative Interface Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Patch, Vendor Advisory |
| Secunia - Advisories - Symantec AntiVirus Scan Engine Administrative Interface Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityReason - Symantec AntiVirus Scan Engine Web Service Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.