Overview
Symantec products are vulnerable to a stack-based buffer overflow. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
Symantec Client Security and Symantec Antivirus Corporate Edition contain a stack-based buffer overflow. For information on specific versions of Symantec Client Security and Symantec Antivirus Corporate Edition that are affected, refer to Symantec Advisory SYM06-010. Note that the affected products typically run with SYSTEM privileges. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code with SYSTEM privileges. |
Solution
Apply updates |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by eEye Digital Security.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-2630 |
Severity Metric: | 24.30 |
Date Public: | 2006-05-24 |
Date First Published: | 2006-05-30 |
Date Last Updated: | 2006-06-13 15:26 UTC |
Document Revision: | 22 |