New User, Welcome!     Login

Norton Internet Security

Symantec Product Security: Symantec Device Driver Local Elevation of Privilege

Some versions of Symantec’s device driver SYMTDI.SYS contain a vulnerability which, if successfully exploited, could allow a local attacker to cause the system to crash. 

Affected Products 
Norton AntiSpam 2005 
Norton AntiVirus 2005, 2006 
Norton Internet Security 2005
Norton Personal Firewall 2005, 2006 
Norton System Works 2005, 2006 
Symantec AntiVirus Corporate Edition 10.0 
Symantec AntiVirus Corporate Edition 10.1, prior to SAV 10.1 MR6 MP1 
Symantec AntiVirus Corporate Edition 9, prior to SAV 9 MR6 MP1  

iDefense Security Advisory 04.02.08: Symantec Internet Security 2008 ActiveDataInfo.LaunchProcess Design Error Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Apr 02, 2008

I. BACKGROUND

Norton Internet Security 2008 is a system security suite that offers
protection from spyware, viruses, identity theft, spam, and malicious
network traffic. More information can be found on the vendor's site at
the following URL.

http://www.symantec.com/home_homeoffice/products/overview.jsp?pcid=is&pvid=nis2008

iDefense Security Advisory 04.02.08: Symantec Norton Internet Security 2008 ActiveX Control Buffer Overflow Vulnerability

http://labs.idefense.com/intelligence/vulnerabilities/
Apr 02, 2008

I. BACKGROUND

Norton Internet Security 2008 is a system security suite that offers
protection from spyware, viruses, identity theft, spam, and malicious
network traffic. More information can be found on the vendor's site at
the following URL.

http://www.symantec.com/home_homeoffice/products/overview.jsp?pcid=is&pvid=nis2008

[G-SEC 47-2009] Symantec generic PDF detection bypass

- Symantec Protection Suite
- Symantec Scan Engine
- Symantec Client Security
- Symantec Endpoint Protection
- Symantec AntiVirus Corporate Edition
- Norton Internet Security
- Norton 360
- Norton AntiVirus
- Norton Systemworks

Patch availability :

Re: DoS attacks on MIME-capable software via complex MIME emails

>== Specific Software ==
>Vulnerable:
>Microsoft Outlook Express 6, Version 6.00.2900.5512
>Opera Version: 9.51 Build: 10081 System: Windows XP
>Incredimail Build ID: 5853710 Setup ID: 7 Pn: 92977368
>Norton Internet Security Version 15.5.0.23
>ESet NOD32 2.70.0039.0000
>Kaspersky Internet Security 2009; Databases from 23.07.2008
>
>Slightly affected:
>Mozilla Thunderbird Version 2.0.14 (20080421)

DoS attacks on MIME-capable software via complex MIME emails

== Specific Software ==
Vulnerable:
Microsoft Outlook Express 6, Version 6.00.2900.5512
Opera Version: 9.51 Build: 10081 System: Windows XP
Incredimail Build ID: 5853710 Setup ID: 7 Pn: 92977368
Norton Internet Security Version 15.5.0.23
ESet NOD32 2.70.0039.0000
Kaspersky Internet Security 2009; Databases from 23.07.2008

Slightly affected:
Mozilla Thunderbird Version 2.0.14 (20080421)

Plague in (security) software drivers & BSDOhook utility

     * BlackICE PC Protection 3.6.cqn
     * G DATA InternetSecurity 2007
     * Ghost Security Suite beta 1.110 and alpha 1.200
     * Kaspersky Internet Security 7.0.0.125
     * Norton Internet Security 2008 15.0.0.60
     * Online Armor Personal Firewall 2.0.1.215
     * Outpost Firewall Pro 4.0.1025.7828
     * Privatefirewall 5.0.14.2
     * Process Monitor 1.22
     * ProcessGuard 3.410

Re: DoS attacks on MIME-capable software via complex MIME emails

brlc> == Specific Software ==
brlc> Vulnerable:
brlc> Microsoft Outlook Express 6, Version 6.00.2900.5512
brlc> Opera Version: 9.51 Build: 10081 System: Windows XP
brlc> Incredimail Build ID: 5853710 Setup ID: 7 Pn: 92977368
brlc> Norton Internet Security Version 15.5.0.23
brlc> ESet NOD32 2.70.0039.0000
brlc> Kaspersky Internet Security 2009; Databases from 23.07.2008

brlc> Slightly affected:
brlc> Mozilla Thunderbird Version 2.0.14 (20080421)

KHOBE - 8.0 earthquake for Windows desktop security software

    * Kaspersky Internet Security 2010 9.0.0.736
    * KingSoft Personal Firewall 9 Plus 2009.05.07.70
    * Malware Defender 2.6.0
    * McAfee Total Protection 2010 10.0.580
    * Norman Security Suite PRO 8.0
    * Norton Internet Security 2010 17.5.0.127
    * Online Armor Premium 4.0.0.35
    * Online Solutions Security Suite 1.5.14905.0
    * Outpost Security Suite Pro 6.7.3.3063.452.0726
    * Outpost Security Suite Pro 7.0.3330.505.1221 BETA VERSION
    * Panda Internet Security 2010 15.01.00



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!