Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages.
Link | Tags |
---|---|
http://securitytracker.com/id?1016842 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28936 | vdb entry |
http://www.securityfocus.com/archive/1/446041/100/0/threaded | mailing list |
http://layereddefense.com/SAV13SEPT.html | |
http://www.securityfocus.com/bid/19986 | vdb entry |
http://secunia.com/advisories/21884 | third party advisory |
http://securityresponse.symantec.com/avcenter/security/Content/2006.09.13.html | patch vendor advisory |
http://www.vupen.com/english/advisories/2006/3599 | vdb entry |
http://www.securityfocus.com/archive/1/446293/100/0/threaded | mailing list |