CVE-2006-0231: Medium severity Symantec AntiVirus Scan Engine vulnerability
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0231?
CVE-2006-0231 is considered a critical vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2006-0231?
To fix CVE-2006-0231, upgrade to Symantec Scan Engine version 5.1.0.7 or later, which uses unique private keys.
What are the potential impacts of CVE-2006-0231?
The potential impacts of CVE-2006-0231 include unauthorized access to encrypted communications and exposure of sensitive information.
Who is affected by CVE-2006-0231?
CVE-2006-0231 affects users of Symantec Scan Engine versions prior to 5.1.0.7, particularly version 5.0.0.24.
What kind of attacks can be executed due to CVE-2006-0231?
Due to CVE-2006-0231, attackers can perform man-in-the-middle attacks, allowing them to intercept and decrypt communications.