Heap-based buffer overflow in the Decomposer component in Symantec Antivirus Products via multiple crafted CAB archivesID: oval:org.secpod.oval:def:9767 | Date: (C)2013-03-18 (M)2021-06-02 |
Class: VULNERABILITY | Family: windows |
The host is installed with Symantec Scan Engine before 5.1.4.24, Symantec Antivirus before 9.0 MR6-MP1, 10.x before 10.1 MR5 MP1 or Symantec Client Security before 2.0 MR6-MP1 or 3.x before 3.1 MR5 MP1 and is prone to heap based buffer overflow vulnerability. A flaw is present in the application, which fails to handle multiple crafted CAB archives. Successful exploitation could allow attackers to execute arbitrary code.
Platform: |
Microsoft Windows 2000 |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Vista |
Microsoft Windows XP |
Product: |
Symantec Antivirus |
Symantec Client Security |
Symantec Scan Engine |