SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

Symantec Antivirus Client Proxy (CLIproxy.dll) buffer overflow


Arrow  WLB : WLB-2010020119  (About)
Arrow  SecurityAlert : None
Arrow  Date : 2010-02-23
Arrow  Credit          : Alexander Polyakov
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2010-02-23] Started

Arrow  Affected software :   Symantec Antivirus



Arrow  Text :  

Digital Security Research Group [DSecRG] Advisory #DSECRG-09-039

Application: Symantec Antivirus Client Proxy
Versions Affected: Version 10
Vendor URL: http://symantec.com
Bugs: Buffer Overflow
Exploits: POC
Reported: 04.05.2009
Vendor response: 07.05.2009
Date of Public Advisory: 17.02.2010
CVE-number: CVE-2010-0108
Author: Alexander Polyakov
Digital Security Research Group [DSecRG]
(research [at] dsecrg [dot] com)

Description
***********

Symantec Antivirus Client Proxy, CLIproxy.dll contains ActiveX component
which is vulnerable to Buffer overflow attack.


Details
*******
http://dsecrg.com/pages/vul/show.php?id=139

Fix Information
***************

Symantec product engineers have released a fix for this issue in the MR9
update. Symantec recommends all customers apply the latest available update
to protect against threats of this nature.
Symantec is not aware of any exploitation of or adverse customer impact
from these issues.


References
**********

Symantec would like to thank Alexander Polyakov from DSecRG for reporting
these issues and coordinating with us while Symantec resolved them.

http://dsecrg.com/pages/vul/show.php?id=139

http://www.symantec.com/business/security_response/securityupdates/detail.j
sp?fid=security_advisory&pvid=security_advisory&year=2010&suid=
20100217_02




About
*****

Digital Security is leading IT security company in Russia, providing
information security consulting, audit and penetration testing services,
risk analysis and ISMS-related services and certification for ISO/IEC
27001:2005 and PCI DSS standards. Digital Security Research Group focuses
on web application and database security problems with vulnerability
reports, advisories and whitepapers posted regularly on our website.


Contact: research [at] dsecrg [dot] com
http://www.dsecrg.com








Polyakov Alexandr. PCI QSA.
Head of security audit department
Head of Digital Security Research Group
______________________
DIGITAL SECURITY
phone: +7 812 703 1547
+7 812 430 9130
e-mail: a.polyakov@dsec.ru
www.dsec.ru
www.dsecrg.com
www.pcidss.ru


-----------------------------------
This message and any attachment are confidential and may be privileged or
otherwise protected
from disclosure. If you are not the intended recipient any use,
distribution, copying or disclosure
is strictly prohibited. If you have received this message in error, please
notify the sender immediately
either by telephone or by e-mail and delete this message and any attachment
from your system. Correspondence
via e-mail is for information purposes only. Digital Security neither makes
nor accepts legally binding
statements by e-mail unless otherwise agreed.
-----------------------------------


Audyt bezpieczeństwa

Security Audit

Analiza powłamaniowa

Arrow  References :  

None

If you want change this note, please use UCP



Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

Copyright © SecurityReason.com. All Rights Reserved.