Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
BID:38222
Info
Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 38222 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0108 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2010 12:00AM |
| Updated: | Mar 09 2010 02:02PM |
| Credit: | Alexander Polyakov from DSecRG |
| Vulnerable: |
Symantec Client Security 3.1.7 .7000 (MR7) Symantec Client Security 3.1.6 .6010 (MR6-MP1) Symantec Client Security 3.1.5 .5010 (MR5-MP1) Symantec Client Security 3.1.5 .5001 (MR5-PP1) Symantec Client Security 3.1.5 .5000 (MR5) Symantec Client Security 3.1.4 MR4 MP1 - build 4010 Symantec Client Security 3.1.4 .4000 (MR4) Symantec Client Security 3.1 .401 Symantec Client Security 3.1 .400 Symantec Client Security 3.1 .396 Symantec Client Security 3.1 .394 Symantec Client Security 3.0.2 .2021 Symantec Client Security 3.0.2 .2020 Symantec Client Security 3.0.2 .2011 Symantec Client Security 3.0.2 .2010 Symantec Client Security 3.0.2 .2002 Symantec Client Security 3.0.2 .2001 Symantec Client Security 3.0.2 .2000 Symantec Client Security 3.0.1 .1009 (MR1-PP9) Symantec Client Security 3.0.1 .1003 (MR1-PP2) Symantec Client Security 3.0 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1.6.6000 Symantec Client Security 3.1 MR8 Symantec Client Security 3.1 MR7 Symantec Client Security 3.1 MR6 MP1 Symantec Client Security 3.1 MR6 Symantec Client Security 3.1 Symantec Client Security 3.0.1.1008 Symantec Client Security 3.0.1.1007 Symantec Client Security 3.0.1.1001 Symantec Client Security 3.0.1.1000 Symantec Client Security 3.0.0.359 Symantec AntiVirus Corporate Edition 10.2.1 .1000 (MR1) Symantec AntiVirus Corporate Edition 10.2 .313 (STM-PP1) Symantec AntiVirus Corporate Edition 10.2 .298 (STM 64-bit) Symantec AntiVirus Corporate Edition 10.2 .276 (STM 32-bit) Symantec AntiVirus Corporate Edition 10.1.7 .7000 (MR7) Symantec AntiVirus Corporate Edition 10.1.6 .6010 (MR6-MP1) Symantec AntiVirus Corporate Edition 10.1.5 .5010 (MR5-MP1) Symantec AntiVirus Corporate Edition 10.1.5 .5001 (MR5-PP1) Symantec AntiVirus Corporate Edition 10.1.5 .5000 (MR5) Symantec AntiVirus Corporate Edition 10.1.4 MR4 MP1 - build 4010 Symantec AntiVirus Corporate Edition 10.1.4 .4000 (MR4) Symantec AntiVirus Corporate Edition 10.1.4 Symantec AntiVirus Corporate Edition 10.1 .401 Symantec AntiVirus Corporate Edition 10.1 .400 Symantec AntiVirus Corporate Edition 10.1 .396 Symantec AntiVirus Corporate Edition 10.1 .394 Symantec AntiVirus Corporate Edition 10.0.2 .2021 Symantec AntiVirus Corporate Edition 10.0.2 .2020 Symantec AntiVirus Corporate Edition 10.0.2 .2011 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2010 Symantec AntiVirus Corporate Edition 10.0.2 .2002 Symantec AntiVirus Corporate Edition 10.0.2 .2001 Symantec AntiVirus Corporate Edition 10.0.2 .2000 Symantec AntiVirus Corporate Edition 10.0.1 .1009 (MR1-PP9) Symantec AntiVirus Corporate Edition 10.0.1 .1003 (MR1-PP2) Symantec AntiVirus Corporate Edition 10.0.1 .1001 (MR1-PP1) Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 10.2 MR3 Symantec AntiVirus Corporate Edition 10.2 MR2 Symantec AntiVirus Corporate Edition 10.2 MR1 Symantec AntiVirus Corporate Edition 10.2 Symantec AntiVirus Corporate Edition 10.1.6.6000 Symantec AntiVirus Corporate Edition 10.1.6.600 Symantec AntiVirus Corporate Edition 10.1.4.4010 Symantec AntiVirus Corporate Edition 10.1 MR8 Symantec AntiVirus Corporate Edition 10.1 MR7 Symantec AntiVirus Corporate Edition 10.1 MR6 MP1 Symantec AntiVirus Corporate Edition 10.1 MR6 Symantec AntiVirus Corporate Edition 10.1 Symantec AntiVirus Corporate Edition 10.0.2.2000 Symantec AntiVirus Corporate Edition 10.0.1.1008 Symantec AntiVirus Corporate Edition 10.0.1.1007 Symantec AntiVirus Corporate Edition 10.0.1.1000 Symantec AntiVirus Corporate Edition 10.0.0.359 |
| Not Vulnerable: |
Symantec Client Security 3.1 MR9 Symantec AntiVirus Corporate Edition 10.2 MR4 Symantec AntiVirus Corporate Edition 10.1 MR9 |
Discussion
Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
The Symantec Client Proxy ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
The following are vulnerable:
Symantec AntiVirus 10.0.x and 10.1.x prior to 10.1 MR9
Symantec AntiVirus 10.2.x prior to 10.2 MR4
Symantec Client Security 3.0.x and 3.1.x prior to 3.1 MR9
The Symantec Client Proxy ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successful exploits allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.
The following are vulnerable:
Symantec AntiVirus 10.0.x and 10.1.x prior to 10.1 MR9
Symantec AntiVirus 10.2.x prior to 10.2 MR4
Symantec Client Security 3.0.x and 3.1.x prior to 3.1 MR9
Exploit / POC
Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Symantec Client Proxy ActiveX Control Buffer Overflow Vulnerability
References:
References:
- [DSECRG-09-039] Symantec Antivirus 10.0 ActiveX - buffer Overflow. (Digital Security Research Group)
- Symantec Homepage (Symantec)
- Security Advisories Relating to Symantec Products - Symantec Client Proxy Buffer (Symantec)