Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
BID:10333
Info
Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
| Bugtraq ID: | 10333 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2004 12:00AM |
| Updated: | May 12 2004 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Derek Soeder. |
| Vulnerable: |
Symantec Norton Personal Firewall 2004 Symantec Norton Personal Firewall 2003 Symantec Norton Personal Firewall 2002 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Norton AntiSpam 2004 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 1.1 Symantec Client Security 1.0 Symantec Client Firewall 5.1.1 Symantec Client Firewall 5.0 1 |
| Not Vulnerable: | |
Discussion
Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
It has been reported that Symantec Client Firewall products may be prone to a remote buffer overflow vulnerability when processing NetBIOS Name Service responses. As a result, an attacker on a local network could respond to a NetBIOS Name Service query from a client and send a malformed response in return that overflows a vulnerable buffer.
A successful attack could allow an attacker to gain SYSTEM level privileges on a vulnerable system.
It has been reported that Symantec Client Firewall products may be prone to a remote buffer overflow vulnerability when processing NetBIOS Name Service responses. As a result, an attacker on a local network could respond to a NetBIOS Name Service query from a client and send a malformed response in return that overflows a vulnerable buffer.
A successful attack could allow an attacker to gain SYSTEM level privileges on a vulnerable system.
Exploit / POC
Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
The discoverers of this issue have produced a proof of concept exploit, however it is not currently in public circulation.
The discoverers of this issue have produced a proof of concept exploit, however it is not currently in public circulation.
Solution / Fix
Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
Solution:
It is reported that a fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
Solution:
It is reported that a fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
References
Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
References:
References: