CVE-2004-0920: Medium severity Symantec Norton Antivirus vulnerability
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0920?
CVE-2004-0920 has a medium severity level due to its potential to allow malicious code to execute undetected or cause denial of service.
How do I fix CVE-2004-0920?
To address CVE-2004-0920, you should upgrade to a later version of Symantec Norton AntiVirus that is no longer vulnerable.
What impact does CVE-2004-0920 have on Symantec Norton AntiVirus?
CVE-2004-0920 can lead to undetected malicious code execution or application crashes due to the use of MS-DOS device names in filenames.
Which versions of Symantec Norton AntiVirus are affected by CVE-2004-0920?
CVE-2004-0920 affects Symantec Norton AntiVirus 2004 and earlier versions.
Can CVE-2004-0920 be exploited remotely?
CVE-2004-0920 can potentially be exploited if an attacker can trick a user into processing a specially crafted filename.