PT-2004-1528 · Symantec · Client Firewall+3
Karl Lynn
·
Published
2004-05-05
·
Updated
2017-07-11
·
CVE-2004-0375
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Norton Internet Security versions 2003 through 2004
Norton Personal Firewall versions 2003 through 2004
Client Firewall versions 5.01 through 5.1.1
Client Security versions 1.0 through 1.1
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, via a TCP packet with specific options. This can be achieved by sending a TCP packet with either the SACK option or the Alternate Checksum Data option followed by a length of zero.
Recommendations
For Symantec Norton Internet Security versions 2003 through 2004, update to a version that includes a fix for this issue.
For Norton Personal Firewall versions 2003 through 2004, update to a version that includes a fix for this issue.
For Client Firewall versions 5.01 through 5.1.1, update to a version that includes a fix for this issue.
For Client Security versions 1.0 through 1.1, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Client Firewall
Client Security
Norton Personal Firewall
Symantec Norton Internet Security