PT-2006-5609 · Symantec · Symantec Ghost+7

David Matousek

·

Publicado

2006-09-19

·

Atualizado

2018-10-17

·

CVE-2006-4855

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Symantec Norton Personal Firewall versions 9.1.0.33 and other versions Symantec Internet Security (affected versions not specified) Symantec AntiVirus (affected versions not specified) Symantec SystemWorks (affected versions not specified) Symantec Client Security SCS versions 1.x through 3.1 Symantec AntiVirus Corporate Edition SAVCE versions 8.x through 10.1 Symantec pcAnywhere version 11.5 Symantec Host (affected versions not specified)
Description The issue allows local users to cause a denial of service, resulting in a system crash, by sending invalid data. This can be achieved by calling DeviceIoControl to send the data.
Recommendations For Symantec Norton Personal Firewall version 9.1.0.33, update to a version that fixes the issue. For Symantec Internet Security, update to a version that fixes the issue. For Symantec AntiVirus, update to a version that fixes the issue. For Symantec SystemWorks, update to a version that fixes the issue. For Symantec Client Security SCS versions 1.x through 3.1, update to a version later than 3.1. For Symantec AntiVirus Corporate Edition SAVCE versions 8.x through 10.1, update to a version later than 10.1. For Symantec pcAnywhere version 11.5, update to a version that fixes the issue. For Symantec Host, update to a version that fixes the issue.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4855

Produtos afetados

Symantec Antivirus
Symantec Antivirus Corporate Edition
Symantec Client Security
Symantec Ghost
Symantec Internet Security
Symantec Norton Personal Firewall
Symantec System Works
Symantec Pcanywhere