CVE-2008-0309: Buffer Overflow
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0309?
CVE-2008-0309 is classified as a critical vulnerability due to its potential to allow remote code execution and application crashes.
How do I fix CVE-2008-0309?
To fix CVE-2008-0309, update the affected Symantec antivirus products to versions 5.1.6.31 or later.
Which software products are affected by CVE-2008-0309?
CVE-2008-0309 affects various Symantec products including Symantec Scan Engine 5.1.2 and earlier versions, as well as Symantec Mail Security for Microsoft Exchange and others listed.
Who can exploit CVE-2008-0309?
CVE-2008-0309 can be exploited by remote attackers using a specially crafted RAR file.
What are the potential impacts of CVE-2008-0309?
The potential impacts of CVE-2008-0309 include the execution of arbitrary code and denial of service due to application crashes.