Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
BID:10334
Info
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
| Bugtraq ID: | 10334 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0444 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery is credited to eEye Digital Security. |
| Vulnerable: |
Symantec Norton Personal Firewall 2004 Symantec Norton Personal Firewall 2003 Symantec Norton Personal Firewall 2002 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Norton AntiSpam 2004 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 1.1 Symantec Client Security 1.0 Symantec Client Firewall 5.1.1 Symantec Client Firewall 5.0 1 |
| Not Vulnerable: | |
Discussion
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
A remotely exploitable buffer overflow vulnerability has been reported in various Symantec Firewall Products. Affected products include Norton Internet Security, Norton Personal Firewall, Norton AntiSpam, Client Firewall, and Client Security.
The issue is due to insufficient bounds checking of DNS response data and may be exploited to gain SYSTEM/kernel level access to a computer hosting the vulnerable software.
The source of the vulnerability is that the CNAME (Canonical Name) data field specified in incoming DNS Resource Records is copied into an internal buffer in an insecure manner, resulting in a stack-based buffer overflow.
A remotely exploitable buffer overflow vulnerability has been reported in various Symantec Firewall Products. Affected products include Norton Internet Security, Norton Personal Firewall, Norton AntiSpam, Client Firewall, and Client Security.
The issue is due to insufficient bounds checking of DNS response data and may be exploited to gain SYSTEM/kernel level access to a computer hosting the vulnerable software.
The source of the vulnerability is that the CNAME (Canonical Name) data field specified in incoming DNS Resource Records is copied into an internal buffer in an insecure manner, resulting in a stack-based buffer overflow.
Exploit / POC
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
The researchers who discovered this issue have developed working exploit code that is not publicly available or known to be circulating in the wild.
The researchers who discovered this issue have developed working exploit code that is not publicly available or known to be circulating in the wild.
Solution / Fix
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
Solution:
It is reported that a fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
Solution:
It is reported that a fix for this vulnerability is available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
References
Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
References:
References:
- SYM04-008 Symantec Client Firewall Remote Access and Denial of Service Issues (Symantec)
- Symantec Multiple Firewall Remote DNS KERNEL Overflow (eEye Digital Security)
- Vulnerability Note VU#294998 - Multiple Symantec firewall (CERT)
- Vulnerability Note VU#637318 - Multiple Symantec firewall (CERT)
- SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues (Sym Security
)