PT-2007-5009 · Symantec · Symantec Client Security+1
Publicado
2007-07-15
·
Atualizado
2017-07-29
·
CVE-2007-3771
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec AntiVirus Corporate Edition versions prior to 10.1
Symantec Client Security versions prior to 3.1
Description
A stack-based buffer overflow issue exists in the Internet E-mail Auto-Protect feature, allowing local users to cause a denial of service by sending an outbound SMTP e-mail message with a long
To, From, or Subject header.Recommendations
For Symantec AntiVirus Corporate Edition versions prior to 10.1, update to version 10.1 or later to resolve the issue.
For Symantec Client Security versions prior to 3.1, update to version 3.1 or later to resolve the issue.
As a temporary workaround, consider restricting the length of
To, From, and Subject headers in outbound SMTP e-mail messages to prevent the denial of service.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Symantec Antivirus Corporate Edition
Symantec Client Security