J-Security Center

Title: Norton Antivirus 2002 Email Scanner Buffer Overflow Vulnerability

Severity: CRITICAL

Description:

Norton Antivirus is a desktop antivirus solution that includes incoming email virus scanning. It is available for Microsoft Operating Systems.

The Norton Antivirus email scanning component is vulnerable to a buffer overflow that could potentially result in arbitrary code execution.

The email scanner scans any files attached to incoming email messages, and can be configured to scan files contained in compressed files. If a file with an unusually long name is contained in a compressed file message attachment, it could cause a buffer in the scanner to be overrun. This could potentially result in the email scanner failing, or arbitrary code execution in the security context of the scanner.

This vulnerability was reported to affect Norton Antivirus 2002, however, earlier versions may also be vulnerable.

Affected Products:

  • Symantec Norton AntiVirus 2002 0.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.