PT-2004-1528 · Symantec · Client Firewall+3

Karl Lynn

·

Published

2004-05-05

·

Updated

2017-07-11

·

CVE-2004-0375

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Symantec Norton Internet Security versions 2003 through 2004 Norton Personal Firewall versions 2003 through 2004 Client Firewall versions 5.01 through 5.1.1 Client Security versions 1.0 through 1.1
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, via a TCP packet with specific options. This can be achieved by sending a TCP packet with either the SACK option or the Alternate Checksum Data option followed by a length of zero.
Recommendations For Symantec Norton Internet Security versions 2003 through 2004, update to a version that includes a fix for this issue. For Norton Personal Firewall versions 2003 through 2004, update to a version that includes a fix for this issue. For Client Firewall versions 5.01 through 5.1.1, update to a version that includes a fix for this issue. For Client Security versions 1.0 through 1.1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0375

Affected Products

Client Firewall
Client Security
Norton Personal Firewall
Symantec Norton Internet Security