Symantec NBNS response buffer overflow
| symantec-nbns-response-bo (16134) |
Description:
Symantec Norton Internet Security is vulnerable to a heap-based buffer overflow, caused by improper bounds checking of the code in the SYMDNS.SYS driver. The SYMDNS.SYS driver validates NetBIOS Name Service (NBNS) responses. If the Symantec products are configured to allow incoming NBNS packets on port 137, which is not enabled by default, a remote attacker could send a specially-crafted NBNS answer packet to cause a denial of service or execute arbitrary code on the system with kernel-level privileges.
Platforms Affected:
- Symantec, Client Firewall 5.01
- Symantec, Client Firewall 5.1.1
- Symantec, Client Security 1.0
- Symantec, Client Security 1.1
- Symantec, Client Security 2.0
- Symantec, Norton AntiSpam 2004
- Symantec, Norton Internet Security 2002 Professional
- Symantec, Norton Internet Security 2002
- Symantec, Norton Internet Security 2003
- Symantec, Norton Internet Security 2003 Professional
- Symantec, Norton Internet Security 2004 Professional
- Symantec, Norton Internet Security 2004
- Symantec, Norton Personal Firewall 2002
- Symantec, Norton Personal Firewall 2003
- Symantec, Norton Personal Firewall 2004
Remedy:
A patch is available for this vulnerability through Symantec LiveUpdate, as listed in Symantec Security Response SYM04-008. See References.
Consequences:
Gain Access
References:
- CIAC Information Bulletin O-141, Symantec Client Firewall Remote Access Vulnerabilities at http://www.ciac.org/ciac/bulletins/o-141.shtml.
- Full-Disclosure Mailing List, Wed May 12 2004 - 19:02:46 CDT, EEYE: Symantec Multiple Firewall NBNS Response Remote Heap Corruption at http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0604.html.
- Symantec Security Response SYM04-008, Symantec Client Firewall Remote Access and Denial of Service Issues at http://securityresponse.symantec.com/avcenter/security/Content/2004.05.12.html.
- BID-10333: Symantec Client Firewall NetBIOS Name Service Response Buffer Overflow Vulnerability
- BID-10334: Symantec Client Firewall DNS Response Buffer Overflow Vulnerability
- BID-10335: Symantec Client Firewall NetBIOS Handler Remote Heap Overflow Vulnerability
- CVE-2004-0444: Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.
- OSVDB ID: 6099: Symantec Multiple Firewall NBNS Response Processing Overflow
- OSVDB ID: 6101: Symantec Multiple Firewall NBNS Response Remote Heap Corruption
- OSVDB ID: 6102: Symantec Multiple Firewall Remote DNS KERNEL Overflow
- SA11066: Symantec Client Firewall Products Multiple Vulnerabilities
- SECTRACK ID: 1010144: Symantec Client Firewall SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
- SECTRACK ID: 1010145: Symantec Client Security SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
- SECTRACK ID: 1010146: Norton AntiSpam SYMDNS.SYS Driver Lets Remote Users Execute Arbitrary Code to Take Full Control of the System
- US-CERT VU#294998: Multiple Symantec firewall products contain a heap corruption vulnerability in the handling of NBNS response packets
- US-CERT VU#634414: Multiple Symantec firewall products fail to properly process NBNS response packets
- US-CERT VU#637318: Multiple Symantec firewall products contain a buffer overflow in the processing of DNS resource records
Reported:
May 12, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
