CVE-2000-0238: Buffer Overflow
Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If the product's web-based management / HTTP interface is not required, disable the embedded web server or web management interface to remove exposure to long-URL buffer overflow attacks.
Norton AntiVirus for Internet Email Gateways (embedded web server) web management interface / HTTP service = disabled - Compensating control
Restrict network access to the product's web server/management port to trusted IP addresses only (firewall/ACLs), and place the interface behind a network segment or VPN. Additionally, deploy a WAF or filtering rules to block or truncate excessively long URL requests to mitigate exploitation attempts.
- Operational
Monitor web server and gateway logs for unusually long URL requests or signs of denial-of-service activity and block offending sources. Apply vendor updates or official patches as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0238?
CVE-2000-0238 is classified as a critical vulnerability due to its ability to lead to denial of service.
How do I fix CVE-2000-0238?
To address CVE-2000-0238, update to a patched version of Norton AntiVirus that resolves the buffer overflow issue.
What impact does CVE-2000-0238 have on system security?
CVE-2000-0238 can allow attackers to exploit the buffer overflow, leading to potential denial of service and system instability.
Which versions of Norton AntiVirus are affected by CVE-2000-0238?
CVE-2000-0238 specifically affects Norton AntiVirus version 1.0 for Internet Email Gateways.
Can CVE-2000-0238 be exploited remotely?
Yes, CVE-2000-0238 can be exploited remotely by sending a specially crafted long URL to the server.