Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/17049 - | |
References | () http://securityreason.com/securityalert/48 - | |
References | () http://securitytracker.com/id?1015001 - | |
References | () http://www.idefense.com/application/poi/display?id=314&type=vulnerabilities - Patch, Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/849209 - US Government Resource | |
References | () http://www.osvdb.org/19854 - | |
References | () http://www.securityfocus.com/bid/15001 - | |
References | () http://www.symantec.com/avcenter/security/Content/2005.10.04.html - Patch, Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2005/1954 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/22519 - |
Information
Published : 2005-10-05 19:02
Updated : 2024-11-21 00:00
NVD link : CVE-2005-2758
Mitre link : CVE-2005-2758
CVE.ORG link : CVE-2005-2758
JSON object : View
Products Affected
symantec
- antivirus_scan_engine
- antivirus_scan_engine_for_network_attached_storage
CWE