Buffer Overrun in Symantec Norton Personal Security Firewall
A buffer overflow vulnerability exists in Symantec's Norton Personal Firewall that an attacker can exploit to execute code on the vulnerable system.
July 15, 2002
Reported July 15, 2002, by@stake.
VERSIONS AFFECTED
· Symantec Norton Personal Firewall 20013.0.4.91 for Windows 2000 and Windows NT 4.0
DESCRIPTION
A buffer overflow vulnerability exists in Symantec's NortonPersonal Firewall that an attacker can exploit to execute code on the vulnerablesystem. An intruder can exploit this vulnerability even if the requestingapplication isn't configured in the firewall permission settings to makeoutgoing requests. See the @stake advisoryfor a detailed technical explanation.
VENDOR RESPONSE
The vendor, Symantec,has released an advisoryregarding this vulnerability and recommends that affected users download thepatch from the advisory URL when the patch becomes available.
CREDIT
Discovered by OllieWhitehouse of @stake.
About the Author
You May Also Like