Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
BID:10336
Info
Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
| Bugtraq ID: | 10336 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0445 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2004 12:00AM |
| Updated: | Sep 05 2006 10:28PM |
| Credit: | Discovery of this vulnerability has been credited to Barnaby Jack, Karl Lynn and Derek Soeder. |
| Vulnerable: |
Symantec Norton Personal Firewall 2004 Symantec Norton Personal Firewall 2003 Symantec Norton Personal Firewall 2002 Symantec Norton Internet Security 2004 Professional Edition Symantec Norton Internet Security 2004 Symantec Norton Internet Security 2003 Professional Edition Symantec Norton Internet Security 2003 Symantec Norton Internet Security 2002 Professional Edition 0 Symantec Norton Internet Security 2002 0 Symantec Norton AntiSpam 2004 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 1.1 Symantec Client Security 1.0 Symantec Client Firewall 5.1.1 Symantec Client Firewall 5.0 1 |
| Not Vulnerable: | |
Discussion
Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
Various Symantec Client Firewall products are prone to a remote denial-of-service vulnerability because the applications fail to properly handle DNS response packets.
Various Symantec Client Firewall products are prone to a remote denial-of-service vulnerability because the applications fail to properly handle DNS response packets.
Exploit / POC
Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
The discoverers of this issue have produced a proof-of-concept exploit, but it is not currently in public circulation.
The following exploit has been publically released:
The discoverers of this issue have produced a proof-of-concept exploit, but it is not currently in public circulation.
The following exploit has been publically released:
Solution / Fix
Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
Solution:
A fix for this vulnerability is reportedly available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
Solution:
A fix for this vulnerability is reportedly available through the Symantec LiveUpdate service. Customers are advised to run LiveUpdate to address this issue.
References
Symantec Client Firewall Remote DNS Response Denial Of Service Vulnerability
References:
References:
- SYM04-008 Symantec Client Firewall Remote Access and Denial of Service Issues (Symantec)
- Symantec Multiple Firewall DNS Response Denial-of-Service (eEye Digital Security)
- Vulnerability Note VU#682110 - Multiple Symantec firewall (CERT)
- SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues (Sym Security
)