Members Login

Rss Feeds

Get our latest content via RSS feeds.

Report a Vulnerability

Report a vulnerability or exploit that you have found to SecuMania.
vul[at]SecuMania.org

 

Latest Comments

I cant say I feel sorry for him, stupid spammer got what he deserved. We all know how it feels to op...
thanks smiley
hi webmaster,plz help me to find any information about account harvesting and traversal path attack ...
Hello Webmasters My name is Nikolai. I am making an organization for the protection internet users f...
good job you are the best . mgharba talmout :d
Hello, The reported problem has been fixed. Regards, Catalina Danila Online Rent Customer Supp...
Not Vulnerable: Luis Wang netOffice Dwins 1.3.1 visit website http://netofficedwins .sourceforge.ne...
Current version of script corrected. Security patch available to registered users in the user foru...
But i think to protect the password is not needed because it's not used in the SQL-Execute statement...
you may find that your hotfix doesnt stop the password field from having SQL injected into it. This ...

Who's Online

Total: 14
Members: 0 / Guests: 14
No members online

Packet Storm

Visits today: 759
Visits yesterday: 943
Visits month: 10679
Visits total: 468058
Pages total: 8769645
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability Print E-mail
0
Thursday, 09 August 2007
Symantec Norton Products NAVCOMUI.DLL ActiveX Control Remote Code Execution Vulnerability
Class: Input Validation Error
CVE: CVE-2007-2955
Remote: Yes
Local: No
Published: Aug 09 2007 12:00AM
Updated: Aug 09 2007 06:04PM
Credit:
Carsten Eiram of Secunia Research reported this issue to the vendor.
Vulnerable:
Symantec Norton System Works 2006
Symantec Norton Internet Security 2006 0
Symantec Norton Internet Security 2005 Anti Spyware Edition 0
Symantec Norton AntiVirus 2006
Not Vulnerable:
Description:
Multiple Symantec Norton products are prone to a remote code-execution vulnerability. This issue occurs in an ActiveX control that is shared across multiple products.

Invoking the object from a malicious website or HTML email may trigger this condition. Successful exploits result in remote code-execution, facilitating the complete compromise of affected computers. Failed exploit attempts likely result in computer crashes.

The following products are vulnerable to this issue:
- Norton Antivirus 2006
- Norton Internet Security 2006
- Norton Internet Security, Anti Spyware Edition 2005
- Norton System Works 2006
Exploit:
Currently SecuMania is not aware of any exploits for this issue.
If you are aware of more recent information, please mail us at: vul[at]SecuMania.org.
Solution:
Symantec has released an advisory and fixes to address this issue. Users of affected packages should use the interactive LiveUpdate feature to obtain and apply fixes.

Please see the references for more information.

References:
Source:
Hits: 95
Comments (0)add
Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

security image
Write the displayed characters


busy
 
< Prev   Next >

Polls

How do you rate the SecuMania Security Portal?
 

web design company
Warning: file_put_contents() failed to open stream: Permission denied in /home/inowweb/public_html/secumania.org/index.php on line 741