|
|
|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0107
The original article can be found at: http://www.securityfocus.com/bid/38217
|
| |
Vulnerable Systems:
* Symantec N360 1.0
* Symantec N3602.0
* Symantec Client Security 3.0.x before 3.1 MR9,
* Symantec Client Security 3.1.x before MR9
Multiple Symantec products are prone to a stack-based buffer-overflow vulnerability because the applications utilize an ActiveX control that fails to adequately validate user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Vendor Status:
Symantec as issued an update for this vulnerablity
Patch Availability:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_01
CVE Information:
CVE-2010-0107
|
|
|
|
|