Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
BID:11328
Info
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
| Bugtraq ID: | 11328 |
| Class: | Design Error |
| CVE: |
CVE-2004-0920 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery is credited to Kurt Seifried. |
| Vulnerable: |
Symantec Norton AntiVirus 2005 Professional Edition Symantec Norton AntiVirus 2005 Symantec Norton AntiVirus 2004 Professional Edition Symantec Norton AntiVirus 2004 Symantec Norton AntiVirus 2003 Professional Edition Symantec Norton Antivirus 2003 0 |
| Not Vulnerable: | |
Discussion
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
Norton AntiVirus is affected by a scan evasion vulnerability when handling files with MS-DOS reserve device names. This issue is due to a design error that allows the files to avoid being scanned. It should be noted that this vulnerability only arises once the file is already present on a vulnerable computer. All Norton AntiVirus products are able to detect malicious files through incoming email.
Norton AntiVirus is affected by a scan evasion vulnerability when handling files with MS-DOS reserve device names. This issue is due to a design error that allows the files to avoid being scanned. It should be noted that this vulnerability only arises once the file is already present on a vulnerable computer. All Norton AntiVirus products are able to detect malicious files through incoming email.
Exploit / POC
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
An exploit is not required to leverage this issue.
An exploit is not required to leverage this issue.
Solution / Fix
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
Solution:
Symantec has released fixes to address this issue. Customers may download updates through Symantec LiveUpdate. Further information is available in the Symantec advisory specified in Web references.
Solution:
Symantec has released fixes to address this issue. Customers may download updates through Symantec LiveUpdate. Further information is available in the Symantec advisory specified in Web references.
References
Symantec Norton AntiVirus MS-DOS Name Scan Evasion Vulnerability
References:
References: