PT-2006-6122 · Symantec · System Works+3
John Heasman
·
Published
2006-10-19
·
Updated
2017-07-20
·
CVE-2006-5403
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symantec Automated Support Assistant versions used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006
Description
A stack-based buffer overflow issue exists in an ActiveX control used by the Symantec Automated Support Assistant. This could allow user-assisted remote attackers to cause a denial of service, potentially leading to a crash, and may also enable the execution of arbitrary code. The attack vectors for this issue are not specified.
Recommendations
For Symantec Automated Support Assistant versions used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, consider disabling the affected ActiveX control as a temporary workaround until a patch is available. Restrict access to the vulnerable ActiveX control to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Security
Norton Antivirus
Symantec Automated Support Assistant
System Works