Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
BID:24802
Info
Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
| Bugtraq ID: | 24802 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3771 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 11 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Jordi Corrales is credited with discovering this issue. |
| Vulnerable: |
Symantec Client Security 3.0.2 .2021 Symantec Client Security 3.0.2 .2020 Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0 Symantec Client Security 2.0.5 build 1100 Symantec Client Security 2.0.4 MR4 build 1000 Symantec Client Security 2.0.4 Symantec Client Security 2.0.3 MR3 b9.0.3.1000 Symantec Client Security 2.0.2 MR2 b9.0.2.1000 Symantec Client Security 2.0.1 MR1 b9.0.1.1000 Symantec Client Security 2.0 STM build 9.0.0.338 Symantec Client Security 2.0 (SCF 7.1) Symantec Client Security 2.0 Symantec Client Security 3.0.1.1008 Symantec Client Security 3.0.1.1007 Symantec Client Security 3.0.1.1001 Symantec Client Security 3.0.1.1000 Symantec Client Security 3.0.0.359 |
| Not Vulnerable: |
Symantec Client Security 2.0.6 MR6 Symantec Client Security 3.1 |
Discussion
Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
Symantec Client Security is prone to a stack-based buffer-overflow vulnerability. This issue occurs because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to cause denial-of-service conditions.
Symantec Client Security is prone to a stack-based buffer-overflow vulnerability. This issue occurs because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to cause denial-of-service conditions.
Exploit / POC
Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
Solution:
Symantec released an advisory and fixes to address this issue. Please see the references for more information.
Solution:
Symantec released an advisory and fixes to address this issue. Please see the references for more information.
References
Symantec Client Security Internet E-mail Auto-Protect Stack Overflow Vulnerability
References:
References:
- Symantec Homepage (Symantec)
- SYM07-016 - Symantec Client Security Internet E-mail Auto-Protect Stack (Symantec)