Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
BID:10335
Info
Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
| Bugtraq ID: | 10335 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0444 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | Discovery of this vulnerability has been credited to eEye Digital Security. |
| Vulnerable: |
Symantec Norton Personal Firewall 2004 Symantec Norton Personal Firewall 2003 Symantec Norton Personal Firewall 2002 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Norton AntiSpam 2004 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 1.1 Symantec Client Security 1.0 Symantec Client Firewall 5.1.1 Symantec Client Firewall 5.0 1 |
| Not Vulnerable: | |
Discussion
Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
Symantec Client Firewall products have been reported prone to a remote heap memory corruption vulnerability. This vulnerability will result in the corruption of inline heap memory management structures, and may ultimately be exploited by a remote attacker to execute arbitrary code on the affected system.
Symantec Client Firewall products have been reported prone to a remote heap memory corruption vulnerability. This vulnerability will result in the corruption of inline heap memory management structures, and may ultimately be exploited by a remote attacker to execute arbitrary code on the affected system.
Exploit / POC
Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
The researchers who discovered this issue have developed working exploit code that is not publicly available or known to be circulating in the wild.
The researchers who discovered this issue have developed working exploit code that is not publicly available or known to be circulating in the wild.
Solution / Fix
References
Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
References:
References:
- SYM04-008 Symantec Client Firewall Remote Access and Denial of Service Issues (Symantec)
- Symantec Multiple Firewall NBNS Response Remote Heap Corruption (eEye Digital Security)
- Vulnerability Note VU#294998 - Multiple Symantec firewall (CERT)
- Vulnerability Note VU#634414 - Multiple Symantec firewall (CERT)
- SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues (Sym Security
)