Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101796 | vdb entry third party advisory |
https://www.info-sec.ca/advisories/Norton-Security.html | third party advisory |
https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20171121_00 | vendor advisory |