PT-2007-5009 · Symantec · Symantec Client Security+1
Published
2007-07-15
·
Updated
2017-07-29
·
CVE-2007-3771
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec AntiVirus Corporate Edition versions prior to 10.1
Symantec Client Security versions prior to 3.1
Description
A stack-based buffer overflow issue exists in the Internet E-mail Auto-Protect feature, allowing local users to cause a denial of service by sending an outbound SMTP e-mail message with a long
To, From, or Subject header.Recommendations
For Symantec AntiVirus Corporate Edition versions prior to 10.1, update to version 10.1 or later to resolve the issue.
For Symantec Client Security versions prior to 3.1, update to version 3.1 or later to resolve the issue.
As a temporary workaround, consider restricting the length of
To, From, and Subject headers in outbound SMTP e-mail messages to prevent the denial of service.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Symantec Antivirus Corporate Edition
Symantec Client Security