CVE-2007-3951: Buffer Overflow
Published Jul 24, 2007
·Updated
Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around."
Affected Software
1 affected component
Norman Norman Virus Control<=5.90
Event History
Jul 24, 2007
CVE Published
05:30 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3951?
CVE-2007-3951 has a critical severity rating, due to its potential for remote code execution.
2
How do I fix CVE-2007-3951?
To fix CVE-2007-3951, upgrade your Norman Antivirus software to a version later than 5.90.
3
What types of files can exploit CVE-2007-3951?
CVE-2007-3951 can be exploited using crafted ACE or LZH files.
4
Who is affected by CVE-2007-3951?
Users of Norman Antivirus version 5.90 or earlier are affected by CVE-2007-3951.
5
What attack vector is used in CVE-2007-3951?
CVE-2007-3951 is exploited through specially crafted files that trigger buffer overflows.