Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
BID:19986
CVE-2006-3454 | CVE-2006-4802 |Info
Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
| Bugtraq ID: | 19986 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3454 CVE-2006-4802 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 13 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | Deral Heiland of Layered Defense discovered the first issue. Symantec engineers found the second format-string issue. |
| Vulnerable: |
Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0 Symantec Client Security 2.0.3 MR3 b9.0.3.1000 Symantec Client Security 2.0.2 MR2 b9.0.2.1000 Symantec Client Security 2.0.1 MR1 b9.0.1.1000 Symantec Client Security 2.0 STM build 9.0.0.338 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 2.0 Symantec Client Security 1.1.1 MR5 build 8.1.1.336 Symantec Client Security 1.1.1 MR4 build 8.1.1.329 Symantec Client Security 1.1.1 MR3 build 8.1.1.323 Symantec Client Security 1.1.1 MR2 build 8.1.1.319 Symantec Client Security 1.1.1 MR1 build 8.1.1.314a Symantec Client Security 1.1.1 MR6 b8.1.1.266 Symantec Client Security 1.1.1 Symantec Client Security 1.1 STM b8.1.0.825a Symantec Client Security 1.1 Symantec Client Security 1.0.1 MR8 build 8.01.471 Symantec Client Security 1.0.1 MR7 build 8.01.464 Symantec Client Security 1.0.1 MR6 build 8.01.460 Symantec Client Security 1.0.1 MR5 build 8.01.457 Symantec Client Security 1.0.1 MR4 build 8.01.446 Symantec Client Security 1.0.1 MR3 build 8.01.434 Symantec Client Security 1.0.1 build 8.01.437 Symantec Client Security 1.0.1 MR9 b8.01.501 Symantec Client Security 1.0.1 MR2 b8.01.429c Symantec Client Security 1.0.1 MR1 b8.01.425a/b Symantec Client Security 1.0.1 Symantec Client Security 1.0 .0 b8.01.9378 Symantec Client Security 1.0 b8.01.9374 Symantec Client Security 1.0 Symantec AntiVirus Corporate Edition 10.0.2 .2011 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2002 Symantec AntiVirus Corporate Edition 10.0.2 .2001 Symantec AntiVirus Corporate Edition 10.0.2 .2000 Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 9.0.5 Symantec AntiVirus Corporate Edition 9.0.4 Symantec AntiVirus Corporate Edition 9.0.3 .1000 Symantec AntiVirus Corporate Edition 9.0.2 .1000 Symantec AntiVirus Corporate Edition 9.0.1 .1.1000 Symantec AntiVirus Corporate Edition 9.0 .0.338 Symantec AntiVirus Corporate Edition 9.0 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.329 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.323 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.319 Symantec AntiVirus Corporate Edition 8.1.1 build 8.1.1.314a Symantec AntiVirus Corporate Edition 8.1.1 .377 Symantec AntiVirus Corporate Edition 8.1.1 .366 Symantec AntiVirus Corporate Edition 8.1.1 Symantec AntiVirus Corporate Edition 8.1 build 8.01.471 Symantec AntiVirus Corporate Edition 8.1 build 8.01.464 Symantec AntiVirus Corporate Edition 8.1 build 8.01.460 Symantec AntiVirus Corporate Edition 8.1 build 8.01.457 Symantec AntiVirus Corporate Edition 8.1 build 8.01.446 Symantec AntiVirus Corporate Edition 8.1 build 8.01.437 Symantec AntiVirus Corporate Edition 8.1 build 8.01.434 Symantec AntiVirus Corporate Edition 8.1 .0.825a Symantec AntiVirus Corporate Edition 8.1 |
| Not Vulnerable: |
Symantec Client Security 3.0.2 .2020 Symantec Client Security 2.0.5 build 1100 Symantec Client Security 1.1.1 build 393 Symantec AntiVirus Corporate Edition 10.0.2 .2020 Symantec AntiVirus Corporate Edition 9.0.5 .1100 Symantec AntiVirus Corporate Edition 8.1.1 build 393 |
Discussion
Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
Symantec AntiVirus Corporate Edition is prone to multiple format-string vulnerabilities because it fails to properly sanitize user-supplied input before using it in the format-specifier argument to a formatted-printing function.
Successfully exploiting these vulnerabilities may allow an attacker to execute arbitrary machine code with SYSTEM-level privileges. Attackers may also crash the Real Time Virus Scan service.
Symantec AntiVirus Corporate Edition is prone to multiple format-string vulnerabilities because it fails to properly sanitize user-supplied input before using it in the format-specifier argument to a formatted-printing function.
Successfully exploiting these vulnerabilities may allow an attacker to execute arbitrary machine code with SYSTEM-level privileges. Attackers may also crash the Real Time Virus Scan service.
Exploit / POC
Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
Solution:
Symantec has released an advisory along with fixes to address these issues. Please see the referenced advisory for more information.
Solution:
Symantec has released an advisory along with fixes to address these issues. Please see the referenced advisory for more information.
References
Symantec AntiVirus Corporate Edition Multiple Local Format String Vulnerabilities
References:
References: