CVE-2006-3454
Summary
| CVE | CVE-2006-3454 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-14 00:07:00 UTC |
| Updated | 2018-10-18 16:47:00 UTC |
| Description | Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Client Security | 1.0 | All | All | All |
| Application | Symantec | Client Security | 1.0.1 | All | All | All |
| Application | Symantec | Client Security | 1.1 | All | All | All |
| Application | Symantec | Client Security | 1.1.1 | All | All | All |
| Application | Symantec | Client Security | 2.0 | All | All | All |
| Application | Symantec | Client Security | 2.0.1 | All | All | All |
| Application | Symantec | Client Security | 2.0.2 | All | All | All |
| Application | Symantec | Client Security | 2.0.3 | All | All | All |
| Application | Symantec | Client Security | 2.0.4 | All | All | All |
| Application | Symantec | Client Security | 3.0 | All | All | All |
| Application | Symantec | Client Security | 1.0 | All | All | All |
| Application | Symantec | Client Security | 1.0.1 | All | All | All |
| Application | Symantec | Client Security | 1.1 | All | All | All |
| Application | Symantec | Client Security | 1.1.1 | All | All | All |
| Application | Symantec | Client Security | 2.0 | All | All | All |
| Application | Symantec | Client Security | 2.0.1 | All | All | All |
| Application | Symantec | Client Security | 2.0.2 | All | All | All |
| Application | Symantec | Client Security | 2.0.3 | All | All | All |
| Application | Symantec | Client Security | 2.0.4 | All | All | All |
| Application | Symantec | Client Security | 3.0 | All | All | All |
| Application | Symantec | Norton Antivirus | 10.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 10.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 8.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.1 | All | corporate | All |
| Application | Symantec | Norton Antivirus | 9.0.2 | All | corporate | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Symantec Anti Virus Corporate Edition Custom Notification Format String Bug Lets Local Users Gain Elevated Privileges | SECTRACK | securitytracker.com | |
| Layered Defense Security Advisories | MISC | layereddefense.com | |
| Symantec Security Center | CONFIRM | securityresponse.symantec.com | Patch, Vendor Advisory |
| Symantec Products Alert Notification Two Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.