CVE-2008-0308: High severity symantec scan engine vulnerability
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0308?
CVE-2008-0308 is categorized as a denial of service vulnerability with medium severity.
How do I fix CVE-2008-0308?
To fix CVE-2008-0308, upgrade to Symantec Scan Engine version 5.1.6.31 or later.
Which Symantec products are affected by CVE-2008-0308?
CVE-2008-0308 affects various Symantec products including Symantec Scan Engine and several versions of Symantec Antivirus.
What type of attack does CVE-2008-0308 enable?
CVE-2008-0308 enables remote attackers to cause a denial of service through memory consumption.
Can malformed RAR files exploit CVE-2008-0308?
Yes, malformed RAR files targeting the ICAP port can exploit CVE-2008-0308.