Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
BID:38217
Info
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 38217 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0107 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Feb 17 2010 12:00AM |
| Credit: | FrSIRT |
| Vulnerable: |
Symantec Norton SystemWorks 2008 0 Symantec Norton SystemWorks 2007 0 Symantec Norton SystemWorks 2006 0 Symantec Norton SystemWorks 2005 Premier 0 Symantec Norton System Works 2006 Symantec Norton Internet Security 2008 0 Symantec Norton Internet Security 2007 0 Symantec Norton Internet Security 2006 Professional Edition Symantec Norton Internet Security 2006 0 Symantec Norton Confidential 2008 0 Symantec Norton Confidential 2007 0 Symantec Norton Confidential 2006 0 Symantec Norton Antivirus 2008 0 Symantec Norton Antivirus 2007 0 Symantec Norton AntiVirus 2006 Symantec Norton 360 2.0 Symantec Norton 360 1.0 Symantec Client Security 3.1.7 .7000 (MR7) Symantec Client Security 3.1.6 .6010 (MR6-MP1) Symantec Client Security 3.1.5 .5010 (MR5-MP1) Symantec Client Security 3.1.5 .5001 (MR5-PP1) Symantec Client Security 3.1.5 .5000 (MR5) Symantec Client Security 3.1.4 MR4 MP1 - build 4010 Symantec Client Security 3.1.4 .4000 (MR4) Symantec Client Security 3.1 .401 Symantec Client Security 3.1 .400 Symantec Client Security 3.1 .396 Symantec Client Security 3.1 .394 Symantec Client Security 3.0.2 .2021 Symantec Client Security 3.0.2 .2020 Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0.1 .1009 (MR1-PP9) Symantec Client Security 3.0.1 .1003 (MR1-PP2) Symantec Client Security 3.0 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1 MR8 Symantec Client Security 3.1 MR7 Symantec Client Security 3.1 MR6 MP1 Symantec Client Security 3.1 MR6 Symantec Client Security 3.1 Symantec Client Security 3.0.1.1008 Symantec Client Security 3.0.1.1007 Symantec Client Security 3.0.1.1001 Symantec Client Security 3.0.1.1000 Symantec Client Security 3.0.0.359 |
| Not Vulnerable: |
Symantec Client Security 3.1 MR9 |
Discussion
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
Multiple Symantec products are prone to a stack-based buffer-overflow vulnerability because the applications utilize an ActiveX control that fails to adequately validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects the following products:
Norton 360 1.0 and 2.0
Norton Internet Security 2006 through 2008
Norton AntiVirus 2006 through 2008
Norton SystemWorks 2006 through 2008
Norton Confidential 2006 through 2008
Symantec Client Security 3.0.x and 3.1.x
Multiple Symantec products are prone to a stack-based buffer-overflow vulnerability because the applications utilize an ActiveX control that fails to adequately validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects the following products:
Norton 360 1.0 and 2.0
Norton Internet Security 2006 through 2008
Norton AntiVirus 2006 through 2008
Norton SystemWorks 2006 through 2008
Norton Confidential 2006 through 2008
Symantec Client Security 3.0.x and 3.1.x
Exploit / POC
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
References
Multiple Symantec Products 'SYMLTCOM.dll' ActiveX Stack Buffer Overflow Vulnerability
References:
References:
- F-Secure Homepage (F-Secure)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Security Advisories Relating to Symantec Products - Input validation errors in S (Symantec)