|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3037
The original article can be found at: http://www.securityfocus.com/bid/36042
|
| |
Vulnerable Systems:
* Symantec Mail Security for SMTP 5.0.1 Patch 201
* Symantec Mail Security for SMTP 5.0.1 Patch 200
* Symantec Mail Security for SMTP 5.0.1 Patch 189
* Symantec Mail Security for SMTP 5.0.1 Patch 182
* Symantec Mail Security for SMTP 5.0.1 Patch 181
* Symantec Mail Security for SMTP 5.0.1
* Symantec Mail Security for SMTP 5.0
* Symantec Mail Security for Microsoft Exchange 6.0.8
* Symantec Mail Security for Microsoft Exchange 6.0.7
* Symantec Mail Security for Microsoft Exchange 6.0.6
* Symantec Mail Security for Microsoft Exchange 5.0.12
* Symantec Mail Security for Microsoft Exchange 5.0.11
* Symantec Mail Security for Microsoft Exchange 5.0.10 .382
* Symantec Mail Security for Microsoft Exchange 5.0.10
* Symantec Mail Security for Domino 7.5.6
* Symantec Mail Security for Domino 8.0
* Symantec Mail Security for Domino 7.5.5.32
* Symantec Mail Security for Domino 7.5.3.25
* Symantec Mail Security Appliance 5.0
* Symantec Mail Security Appliance 5.0.0.24
* Symantec Mail Security Appliance 5.0.0-36
* Symantec Mail Security Appliance 5.0.0-36
* Symantec Data Loss Prevention Endpoint Agents 9.0.1
* Symantec Data Loss Prevention Endpoint Agents 8.1.1
* Symantec Data Loss Prevention Detection Servers for Windows 9.0.1
* Symantec Data Loss Prevention Detection Servers for Windows 8.1.1
* Symantec Data Loss Prevention Detection Servers for Linux 9.0.1
* Symantec Data Loss Prevention Detection Servers for Linux 8.1.1
* Symantec Data Loss Prevention Detection Servers 7.2
* Symantec BrightMail Appliance 8.0.1
* Symantec BrightMail Appliance 8.0
* Symantec BrightMail Appliance 5.0
Autonomy KeyView module is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data before copying it to insufficiently sized buffers.
Exploiting this issue will allow an attacker to corrupt memory and cause denial-of-service conditions or potentially to execute arbitrary code in the context of an application using the module. Multiple products using the KeyView module are affected.
Vendor Status:
Symantec as issued an update for this vulnerablity
Patch Availability:
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090825_00
CVE Information:
CVE-2009-3037
|
|
|