First published: Wed Oct 06 2004(Updated: )
Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause a denial of service (application crash) using a filename containing an MS-DOS device name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Antivirus | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0920 has a medium severity level due to its potential to allow malicious code to execute undetected or cause denial of service.
To address CVE-2004-0920, you should upgrade to a later version of Symantec Norton AntiVirus that is no longer vulnerable.
CVE-2004-0920 can lead to undetected malicious code execution or application crashes due to the use of MS-DOS device names in filenames.
CVE-2004-0920 affects Symantec Norton AntiVirus 2004 and earlier versions.
CVE-2004-0920 can potentially be exploited if an attacker can trick a user into processing a specially crafted filename.