Symantec AntiVirus and Client Security remote management interface buffer overflow
| symantec-antivirus-client-bo (26706) |
Description:
Symantec AntiVirus Corporate Edition and Symantec Client Security are vulnerable to a stack-based buffer overflow in the remote management interface. A remote or local attacker could exploit this vulnerability to execute arbitrary code on the system with SYSTEM level privileges or cause the system to crash.
Platforms Affected:
- Symantec, AntiVirus 10.0 Corporate
- Symantec, AntiVirus 10.0.2.2010 Corporate
- Symantec, AntiVirus 10.0.2.2020 Corporate
- Symantec, AntiVirus 10.0.2.2021 Corporate
- Symantec, AntiVirus 10.1 Corporate
- Symantec, AntiVirus 10.1.400 Corporate
- Symantec, Client Security 3.0
- Symantec, Client Security 3.0.2.2010
- Symantec, Client Security 3.0.2.2020
- Symantec, Client Security 3.1
- Symantec, Client Security 3.1.394
- Symantec, Client Security 3.1.400
Remedy:
Upgrade to the latest version of Symantec Client Security or Symantec AntiVirus Corporate Edition, as listed in Symantec Security Response Advisory SYM06-010. See References.
Consequences:
Gain Access
References:
- BugTraq Mailing List, Fri May 26 2006 - 19:18:45 CDT , Symantec antivirus software exposes computers at http://archives.neohapsis.com/archives/bugtraq/2006-05/0608.html.
- eEye Digital Security Advisory AD20060612, Symantec Remote Management Stack Buffer Overflow at http://www.eeye.com/html/research/advisories/AD20060612.html.
- Full-Disclosure Mailing List, Fri May 26 2006 - 11:40:07 CDT, new symantec vuln at http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0673.html.
- Internet Security Systems Protection Alert June 2, 2006, Symantec AntiVirus and Client Security buffer overflow at http://xforce.iss.net/xforce/alerts/id/223.
- Symantec Security Response Advisory SYM06-010, Symantec Client Security and Symantec AntiVirus Elevation of Privilege at http://securityresponse.symantec.com/avcenter/security/Content/2006.05.25.html.
- BID-18107: Symantec AntiVirus Remote Stack Buffer Overflow Vulnerability
- CVE-2006-2630: Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitrary code via unknown attack vectors.
- SA20318: Symantec Client Security / AntiVirus Management Interface Buffer Overflow
- SECTRACK ID: 1016161: Symantec Client Security Stack Overflow Lets Remote Users Execute Arbitrary Code
- SECTRACK ID: 1016162: Symantec AntiVirus Corporate Edition Stack Overflow Lets Remote Users Execute Arbitrary Code
- US-CERT VU#404910: Symantec products vulnerable to buffer overflow
- VUPEN/ADV-2006-2005: Symantec AntiVirus and Client Security Remote Buffer Overflow Vulnerability
Reported:
May 25, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2009 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
