CVE-2005-3270: High severity Symantec Norton Antivirus vulnerability
Published Oct 20, 2005
·Updated
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
Affected Software
1 affected component
Symantec Norton Antivirus=9.0.3
Event History
Oct 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3270?
CVE-2005-3270 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2005-3270?
To mitigate CVE-2005-3270, ensure that the PATH variable does not point to any untrusted directories.
3
Who is affected by CVE-2005-3270?
CVE-2005-3270 affects users of Symantec Norton AntiVirus version 9.0.3 on Macintosh systems.
4
What types of attacks can exploit CVE-2005-3270?
CVE-2005-3270 can be exploited by local users to run malicious versions of system commands.
5
Is there a patch available for CVE-2005-3270?
As of my knowledge cutoff, there is no specific patch for CVE-2005-3270; reducing PATH exposure is advised.