Buffer Overrun in Symantec Norton Personal Security Firewall

A buffer overflow vulnerability exists in Symantec's Norton Personal Firewall that an attacker can exploit to execute code on the vulnerable system.

Ken Pfeil

July 15, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported July 15, 2002, by@stake.

VERSIONS AFFECTED

 

·        Symantec Norton Personal Firewall 20013.0.4.91 for Windows 2000 and Windows NT 4.0

 

DESCRIPTION


A buffer overflow vulnerability exists in Symantec's NortonPersonal Firewall that an attacker can exploit to execute code on the vulnerablesystem. An intruder can exploit this vulnerability even if the requestingapplication isn't configured in the firewall permission settings to makeoutgoing requests. See the @stake advisoryfor a detailed technical explanation.

 

VENDOR RESPONSE

The vendor, Symantec,has released an advisoryregarding this vulnerability and recommends that affected users download thepatch from the advisory URL when the patch becomes available.

 

CREDIT
Discovered by OllieWhitehouse of @stake.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like