CVE-2000-1007: Medium severity Symantec I-gear vulnerability
Published Dec 11, 2000
·Updated
I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.
Affected Software
2 affected components
Symantec I-gear=3.5.7
Symantec I-gear=3.5
Remediation
Event History
Dec 11, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1007?
CVE-2000-1007 is considered to have a moderate severity due to its potential for creating reporting errors.
2
How do I fix CVE-2000-1007?
To fix CVE-2000-1007, upgrade to a version of Symantec I-gear later than 3.5.7.
3
What versions of I-gear are affected by CVE-2000-1007?
CVE-2000-1007 affects Symantec I-gear versions 3.5 and earlier.
4
What type of attack does CVE-2000-1007 enable?
CVE-2000-1007 allows attackers to exploit logging errors triggered by excessively long URLs.
5
Can CVE-2000-1007 be exploited remotely?
Yes, CVE-2000-1007 can be exploited remotely if an attacker sends a specially crafted URL exceeding 255 characters.