Published:2005/03/29  Last Updated:2008/05/21

JVN#C45D8EAD
Norton AntiVirus causes abnormal OS termination when scanning illegal files

Overview

Symantec Norton AntiVirus 2004 and 2005 contain a vulnerability that causes an abnormal operating system termination of a computer, when their real-time scan feature is enabled and examining a file with a specially crafted file header.

Products Affected

  • Symantec Norton AntiVirus 2004
  • Symantec Norton Internet Security 2004 (Professional)
  • Symantec Norton System Works 2004 (Professional)
  • Symantec Norton AntiVirus 2005
  • Symantec Norton Internet Security 2005
  • Symantec Norton System Works 2005 (Premier)

Description

Impact

An attacker could cause an abnormal OS termination by sending a file with a specially crafted file header.

Solution

Vendor Status

Vendor Status Last Update Vendor Notes
Symantec Japan, Inc. Vulnerable 2005/03/30

References

JPCERT/CC Addendum

Credit

Isamu Noguchi reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2005-0922
JVN iPedia JVNDB-2005-000762

Update History