CVE-2006-6490

Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478
http://osvdb.org/33481
http://osvdb.org/33482
http://secunia.com/advisories/24246
http://secunia.com/advisories/24251
http://www.kb.cert.org/vuls/id/441785 US Government Resource
http://www.securityfocus.com/archive/1/461147/100/0/threaded
http://www.securityfocus.com/bid/22564
http://www.securitytracker.com/id?1017688
http://www.securitytracker.com/id?1017689
http://www.securitytracker.com/id?1017690
http://www.securitytracker.com/id?1017691
http://www.symantec.com/avcenter/security/Content/2007.02.22.html Patch
http://www.vupen.com/english/advisories/2007/0703
http://www.vupen.com/english/advisories/2007/0704
https://exchange.xforce.ibmcloud.com/vulnerabilities/32636
http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478
http://osvdb.org/33481
http://osvdb.org/33482
http://secunia.com/advisories/24246
http://secunia.com/advisories/24251
http://www.kb.cert.org/vuls/id/441785 US Government Resource
http://www.securityfocus.com/archive/1/461147/100/0/threaded
http://www.securityfocus.com/bid/22564
http://www.securitytracker.com/id?1017688
http://www.securitytracker.com/id?1017689
http://www.securitytracker.com/id?1017690
http://www.securitytracker.com/id?1017691
http://www.symantec.com/avcenter/security/Content/2007.02.22.html Patch
http://www.vupen.com/english/advisories/2007/0703
http://www.vupen.com/english/advisories/2007/0704
https://exchange.xforce.ibmcloud.com/vulnerabilities/32636
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:supportsoft:scriptrunner:*:*:*:*:*:*:*:*
cpe:2.3:a:supportsoft:smartissue:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:automated_support_assistant:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_system_works:2006:*:*:*:*:*:*:*

History

21 Nov 2024, 00:22

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html - () http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html -
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478 -
References () http://osvdb.org/33481 - () http://osvdb.org/33481 -
References () http://osvdb.org/33482 - () http://osvdb.org/33482 -
References () http://secunia.com/advisories/24246 - () http://secunia.com/advisories/24246 -
References () http://secunia.com/advisories/24251 - () http://secunia.com/advisories/24251 -
References () http://www.kb.cert.org/vuls/id/441785 - US Government Resource () http://www.kb.cert.org/vuls/id/441785 - US Government Resource
References () http://www.securityfocus.com/archive/1/461147/100/0/threaded - () http://www.securityfocus.com/archive/1/461147/100/0/threaded -
References () http://www.securityfocus.com/bid/22564 - () http://www.securityfocus.com/bid/22564 -
References () http://www.securitytracker.com/id?1017688 - () http://www.securitytracker.com/id?1017688 -
References () http://www.securitytracker.com/id?1017689 - () http://www.securitytracker.com/id?1017689 -
References () http://www.securitytracker.com/id?1017690 - () http://www.securitytracker.com/id?1017690 -
References () http://www.securitytracker.com/id?1017691 - () http://www.securitytracker.com/id?1017691 -
References () http://www.symantec.com/avcenter/security/Content/2007.02.22.html - Patch () http://www.symantec.com/avcenter/security/Content/2007.02.22.html - Patch
References () http://www.vupen.com/english/advisories/2007/0703 - () http://www.vupen.com/english/advisories/2007/0703 -
References () http://www.vupen.com/english/advisories/2007/0704 - () http://www.vupen.com/english/advisories/2007/0704 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/32636 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/32636 -

Information

Published : 2007-02-22 21:28

Updated : 2024-11-21 00:22


NVD link : CVE-2006-6490

Mitre link : CVE-2006-6490

CVE.ORG link : CVE-2006-6490


JSON object : View

Products Affected

symantec

  • norton_antivirus
  • norton_internet_security
  • automated_support_assistant
  • norton_system_works

supportsoft

  • smartissue
  • scriptrunner