First published: Thu Feb 28 2008(Updated: )
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Antivirus Filtering for Domino | <=3.0.12 | |
Symantec Mail Security for Microsoft Exchange | <=4.6.5.12 | |
Symantec Antivirus Filtering for Domino | <=3.0.12 | |
Symantec Antivirus Scan Engine | <=4.3.16.39 | |
Symantec Antivirus Scan Engine | <=4.3.16.39 | |
Symantec Scan Engine | <=4.3.16.39 | |
Symantec Scan Engine | <=5.1.4.24 | |
Symantec Antivirus Scan Engine for Microsoft SharePoint | <=4.3.16.39 | |
Symantec Antivirus Scan Engine | <=4.3.16.39 | |
Symantec Antivirus Scan Engine | <=4.3.16.39 | |
Symantec Antivirus Filtering for Domino | <=3.0.12 | |
Symantec Mail Security for Microsoft Exchange | <=5.0.4.363 | |
Symantec Antivirus for Network Attached Storage | <=4.3.16.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0309 is classified as a critical vulnerability due to its potential to allow remote code execution and application crashes.
To fix CVE-2008-0309, update the affected Symantec antivirus products to versions 5.1.6.31 or later.
CVE-2008-0309 affects various Symantec products including Symantec Scan Engine 5.1.2 and earlier versions, as well as Symantec Mail Security for Microsoft Exchange and others listed.
CVE-2008-0309 can be exploited by remote attackers using a specially crafted RAR file.
The potential impacts of CVE-2008-0309 include the execution of arbitrary code and denial of service due to application crashes.