First published: Tue Jul 24 2007(Updated: )
Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Norman Norman Virus Control | <=5.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3951 has a critical severity rating, due to its potential for remote code execution.
To fix CVE-2007-3951, upgrade your Norman Antivirus software to a version later than 5.90.
CVE-2007-3951 can be exploited using crafted ACE or LZH files.
Users of Norman Antivirus version 5.90 or earlier are affected by CVE-2007-3951.
CVE-2007-3951 is exploited through specially crafted files that trigger buffer overflows.