Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
BID:13416
Info
Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
| Bugtraq ID: | 13416 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2005 12:00AM |
| Updated: | Apr 28 2005 12:00AM |
| Credit: | André Jerleke a.k.a. Phiberz <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Symantec Web Security 3.0.1 build 3.0.1.72 Symantec SAV/Filter for Domino NT 3.1 build 3.1.1.87 Symantec Norton AntiVirus 2005 11.0 Symantec Mail Security For Smtp 4.0 build 4.0.5.66 Symantec Mail Security For Microsoft Exchange 4.5 build 4.5.4.743 Symantec AntiVirus Scan Engine 4.3 build 4.3.7.27 |
| Not Vulnerable: |
Symantec Web Security 3.0.1 build 3.0.1.74 Symantec SAV/Filter for Domino NT 3.1 build 3.1.2.91 Symantec Norton AntiVirus 2005 11.0.9 Symantec Mail Security For Smtp 4.0 build 4.1.4.30 Symantec Mail Security For Microsoft Exchange 4.6 build 4.6.1.107 Symantec AntiVirus Scan Engine 4.3 build 4.3.8.29 |
Discussion
Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
A scan evasion denial of service vulnerability affects Symantec AntiVirus. This issue is due to a failure of the application to properly handle malformed files.
An attacker may leverage this issue to crash the file scanner of the affected antivirus software, causing the file scanner to fail to detect malicious code contained therein.
A scan evasion denial of service vulnerability affects Symantec AntiVirus. This issue is due to a failure of the application to properly handle malformed files.
An attacker may leverage this issue to crash the file scanner of the affected antivirus software, causing the file scanner to fail to detect malicious code contained therein.
Exploit / POC
Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
Solution:
Symantec has released advisory SYM05-007 along with upgrades dealing with this issue. Please see the reference section for more information.
Solution:
Symantec has released advisory SYM05-007 along with upgrades dealing with this issue. Please see the reference section for more information.
References
Symantec AntiVirus RAR Archive Scan Evasion Denial Of Service Vulnerability
References:
References:
- SYM05-007 - Symantec AntiVirus RAR archive bypass (Symantec)
- Symantec Homepage (Symantec)