|
Symantec Support Tool ActiveX Control Vulnerabilities
|
|
Secunia Advisory:
|
SA22228
|
|
|
Release Date:
|
2006-10-06
|
|
Last Update:
|
2006-10-27
|
|
Popularity:
|
11,335 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of system information System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Symantec Automated Support Assistant Symantec Norton AntiVirus 2005 Symantec Norton AntiVirus 2006 Symantec Norton Internet Security 2005 Symantec Norton Internet Security 2006 Symantec Norton SystemWorks 2005 Symantec Norton SystemWorks 2006
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Some vulnerabilities have been reported in Support Tool ActiveX Control included in various Symantec products, which potentially can be exploited by malicious people to disclose system information or to compromise a vulnerable system.
1) An unspecified input validation error exists, which can be exploited to gain unauthorized access to system information.
2) An unspecified boundary error exist, which can be exploited to cause a stack-based buffer overflow and may allow execution of arbitrary code with privileges of the user running the browser.
Successful exploitation requires spoofing of a trusted domain web site and to trick the user to click on a malicious link.
The following products are affected:
* Symantec Automated Support Assistant
* Symantec Norton AntiVirus 2005, 2006
* Symantec Norton Internet Security 2005, 2006
* Symantec Norton SystemWorks 2005, 2006
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|