CVE-2005-0249

Published Feb 8, 2005

Last updated 16 days ago

Overview

Description
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
Source
cve@mitre.org
NVD status
Modified
Products
antivirus_scan_engine, brightmail_antispam, client_security, gateway_security, mail_security, norton_antivirus, norton_internet_security, norton_system_works, sav_filter_domino_nt_ports, sav_filter_for_domino_nt, web_security

Risk scores

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations