CVE-2005-0249: Buffer Overflow

Published Feb 8, 2005
·
Updated

Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.

Affected Software

49 affected components
Symantec AntiVirus Scan Engine<4.3.3
Symantec Brightmail AntiSpam=4.0
Symantec Brightmail AntiSpam=5.5
Symantec Client Security=1.0.1_build_8.01.434-mr3
Symantec Client Security=1.0.1_build_8.01.437
Symantec Client Security=1.0.1_build_8.01.446-mr4
Symantec Client Security=1.0.1_build_8.01.457-mr5
Symantec Client Security=1.0.1_build_8.01.460-mr6
Symantec Client Security=1.0.1_build_8.01.464-mr7
Symantec Client Security=1.0.1_build_8.01.471-mr8
Symantec Client Security=1.1.1_mr1_build_8.1.1.314a
Symantec Client Security=1.1.1_mr2_build_8.1.1.319
Symantec Client Security=1.1.1_mr3_build_8.1.1.323
Symantec Client Security=1.1.1_mr4_build_8.1.1.329
Symantec Client Security=1.1.1_mr5_build_8.1.1.336
Symantec Gateway Security=1.0
Symantec Gateway Security=2.0
Symantec Gateway Security=2.0.1
Symantec Mail Security=4.0
Symantec Mail Security=4.1-build_458
Symantec Mail Security=4.1-build_459
Symantec Mail Security=4.1-build_461
Symantec Mail Security=4.5_build_719
Symantec Norton Antivirus=2.18_build_83
Symantec Norton Antivirus=8.1.1.319
Symantec Norton Antivirus=8.1.1.323
Symantec Norton Antivirus=8.1.1.329
Symantec Norton Antivirus=8.1.1_build8.1.1.314a
Symantec Norton Antivirus=8.01.434
Symantec Norton Antivirus=8.01.437
Symantec Norton Antivirus=8.01.446
Symantec Norton Antivirus=8.01.457
Symantec Norton Antivirus=8.01.460
Symantec Norton Antivirus=8.01.464
Symantec Norton Antivirus=8.01.471
Symantec Norton Antivirus=9.0
Symantec Norton Antivirus=2004
Symantec Norton Internet Security=2004
Symantec Norton System Works=2004
Symantec Sav Filter Domino Nt Ports=build3.0.5
Symantec Sav Filter Domino Nt Ports=build3.0.5
Symantec Sav Filter For Domino Nt=3.1.1
Symantec Web Security=3.01.59
Symantec Web Security=3.01.60
Symantec Web Security=3.01.61
Symantec Web Security=3.01.62
Symantec Web Security=3.01.63
Symantec Web Security=3.01.67
Symantec Web Security=3.01.68

Event History

Feb 8, 2005
CVE Published
05:00 AM
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2005-0249?

CVE-2005-0249 is classified as a critical vulnerability due to the potential for remote code execution.

2

How do I fix CVE-2005-0249?

To fix CVE-2005-0249, it is recommended to update all affected Symantec products to their latest versions that contain the security patches.

3

Which products are affected by CVE-2005-0249?

CVE-2005-0249 affects several Symantec products, including Norton Internet Security 2004, Norton Antivirus, and Client Security versions.

4

Can CVE-2005-0249 be exploited remotely?

Yes, CVE-2005-0249 can be exploited remotely through specially crafted UPX compressed files.

5

What types of attacks can CVE-2005-0249 enable?

CVE-2005-0249 enables attackers to perform arbitrary code execution on the targeted system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203