First published: Wed May 16 2007(Updated: )
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Internet Security | =2004 | |
Symantec Norton Personal Firewall | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1689 has a critical severity level due to the buffer overflow allowing remote code execution.
To fix CVE-2007-1689, users should update to a patched version of Norton Personal Firewall or Norton Internet Security.
CVE-2007-1689 affects Norton Internet Security 2004 and Norton Personal Firewall 2004.
CVE-2007-1689 is classified as a buffer overflow vulnerability in the ISAlertDataCOM ActiveX control.
Yes, CVE-2007-1689 can be exploited remotely, allowing attackers to execute arbitrary code.