VULNERABILITIES - March 29, 2005
by roddy32
- 3/29/05 6:09 AM
TITLE:
Symantec Norton AntiVirus Denial of Service Vulnerabilities
SECUNIA ADVISORY ID:
SA14741
VERIFY ADVISORY:
http://secunia.com/advisories/14741/
CRITICAL:
Less critical
IMPACT:
DoS
WHERE:
From remote
SOFTWARE:
Symantec Norton SystemWorks 2005
http://secunia.com/product/4847/
Symantec Norton AntiVirus 2004
http://secunia.com/product/2800/
Symantec Norton AntiVirus 2005
http://secunia.com/product/4009/
Symantec Norton Internet Security 2004 Professional
http://secunia.com/product/2442/
Symantec Norton Internet Security 2005
http://secunia.com/product/4848/
Symantec Norton SystemWorks 2004
http://secunia.com/product/2796/
DESCRIPTION:
Isamu Noguchi has reported two vulnerabilities in Symantec Norton
AntiVirus, which can be exploited by malicious people to cause a DoS
(Denial of Service).
1) An unspecified error in the Auto-Protect module during scan of
specific file types can be exploited to cause the system to hang or
crash.
2) An error in the SmartScan feature in Auto-Protect, when a file
located on a network share is renamed, can be exploited to consume a
large amount of CPU resources or cause a system crash.
The following products are affected:
* Symantec Norton AntiVirus 2004
* Symantec Norton Internet Security 2004 (Professional)
* Symantec Norton SystemWorks 2004 (Professional)
* Symantec Norton AntiVirus 2005
* Symantec Norton Internet Security 2005
* Symantec Norton SystemWorks 2005 (Premier)
SOLUTION:
The vendor has issued a fix, which is available via LiveUpdate.
PROVIDED AND/OR DISCOVERED BY:
Isamu Noguchi
ORIGINAL ADVISORY:
Symantec:
http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html


Moderator
CNET Staff
Samsung Staff
Dell Staff