CVE-2006-3454: High severity Symantec Client Security vulnerability
Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3454?
CVE-2006-3454 has a high severity due to its potential to allow local users to execute arbitrary code.
How do I fix CVE-2006-3454?
To fix CVE-2006-3454, users should upgrade to the latest version of Symantec AntiVirus or Client Security that addresses this vulnerability.
What software is affected by CVE-2006-3454?
CVE-2006-3454 affects Symantec AntiVirus Corporate Edition versions 8.1 to 10.0 and Symantec Client Security versions 1.x to 3.0.
What are the consequences of CVE-2006-3454?
The consequences of CVE-2006-3454 include the risk of arbitrary code execution, which may lead to unauthorized access or control over the system.
Who can exploit CVE-2006-3454?
Local users can exploit the vulnerabilities in CVE-2006-3454 by using specially crafted format strings.