Title: Norton Antivirus 2000 POProxy USER Vulnerability
Severity: CRITICAL
Description:
Norton Anti-Virus 2000 is a widely used commercial anti-virus application. POProxy is its integral e-mail scanner, which is implemented by selecting 'e-mail protection'.
POProxy behaves as a proxy for a POP server, listening on port 110. When users request their email, the request is proxied through POProxy and all mail passing through it is scanned for viruses.
A buffer overflow exists which can be exploited if the attacker sends 269 characters or more to the service. This causes poproxy.exe to crash and clients can not use it to retrieve any incoming mail until it is restarted or the system is rebooted.
In addition to causing a denial of service, it may be possible to exploit this vulnerability to execute arbitrary code on the server.
Affected Products:
- Symantec Norton AntiVirus 0.0.02000
References:
- Symantec: New LiveUpdate Patch Removes Alleged Security Hole Created by the Norton AntiVir
- Symantec: Norton AntiVirus 2000 for Windows 95/98/2000/NT Product Info
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.