First published: Thu Dec 11 2008(Updated: )
Norton Antivirus in Norton Internet Security 15.5.0.23 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Norton Internet Security | =15.5.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5427 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2008-5427, it is recommended to update to a newer version of Norton Internet Security, as version 15.5.0.23 is affected.
CVE-2008-5427 is a denial-of-service vulnerability that affects the handling of certain e-mail message types.
CVE-2008-5427 specifically affects Symantec Norton Internet Security version 15.5.0.23.
Yes, CVE-2008-5427 can be exploited remotely by sending specially crafted e-mail messages.