CVE-2004-2147: Medium severity symantec norton antivirus vulnerability
Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2147?
CVE-2004-2147 has been classified as a denial of service vulnerability, allowing attackers to crash the affected applications.
How do I fix CVE-2004-2147?
To fix CVE-2004-2147, update to the latest version of Symantec Norton AntiVirus or apply any patches provided by the vendor.
Which software is affected by CVE-2004-2147?
CVE-2004-2147 affects multiple versions of Symantec Norton AntiVirus and Microsoft Outlook, particularly older releases from 2001 to 2004.
Can CVE-2004-2147 be exploited through email?
Yes, CVE-2004-2147 can be exploited by sending malformed email messages that either lack a body or do not have a carriage return separating the headers and body.
Is there a workaround for CVE-2004-2147?
As a workaround for CVE-2004-2147, users can limit the use of affected email clients until proper updates are applied.