CVE-1999-1004: Buffer Overflow
Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Symantec Norton AntiVirusfrom your environment.Uninstall Norton AntiVirus (NAV2000) from systems where it is not required to eliminate the vulnerable POProxy component.
- Configuration
Disable or stop the POProxy POP3 server/service provided by Norton AntiVirus (NAV2000) to prevent exploitation via a large USER command.
Symantec Norton AntiVirus (POProxy POP server) POProxy/POP3 service = disabled - Compensating control
Block or restrict access to POP3 (TCP port 110) to affected hosts (or specifically to the POProxy service) at the network perimeter or host-based firewall to prevent remote exploitation.
- Operational
Monitor Symantec vendor advisories for a vendor-supplied patch or fixed version for NAV2000 and apply the update as soon as it is released; maintain the above mitigations until patched.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1004?
CVE-1999-1004 is rated as a high-severity vulnerability due to its potential to allow unauthorized access through a buffer overflow.
How do I fix CVE-1999-1004?
To fix CVE-1999-1004, you should update the Norton Anti-Virus software to the latest version available from Symantec.
What systems are affected by CVE-1999-1004?
CVE-1999-1004 specifically affects the Symantec Norton Anti-Virus 2000 software.
What types of attacks are possible with CVE-1999-1004?
Exploitation of CVE-1999-1004 can potentially allow remote attackers to execute arbitrary code on the target system.
Is CVE-1999-1004 still a threat today?
While CVE-1999-1004 was a significant issue in its time, the threat level today is largely mitigated due to the outdated status of Norton Anti-Virus 2000 and subsequent software updates.