Intrusion Prevention

Symantec.AntiVirus.RAR.Decompression.Heap.Overflow

Description

Multiple Symantec Antivirus products that use the Symantec Antivirus Library have a heap-overflow vulnerability. A remote attacker can excute arbitrary code via a RAR archives with sub block headers that contain in correct values of the block size and data size.

Affected Products

Symantec AntiSpam for SMTP 3.1
Symantec AntiVirus Corporate Edition 10
Symantec AntiVirus for Caching 4.3.12 and prior
Symantec AntiVirus for Clearswift 4.3.12 and prior
Symantec AntiVirus for Handhelds
Symantec AntiVirus for HandHelds - Corporate Edition
Symantec AntiVirus for Messaging 4.3.12
Symantec AntiVirus for MS ISA 4.3.12
Symantec AntiVirus for MS Sharepoint 4.3.12
Symantec AntiVirus for NAS 4.3.12
Symantec AntiVirus for SMTP 3.1
Symantec AntiVirus for SMTP 4
Symantec AntiVirus for SMTP 4.1.9
Symantec AntiVirus Scan Engine 4.1.8
Symantec AntiVirus Scan Engine 4.3
Symantec AntiVirus Scan Engine 4.3.12
Symantec AntiVirus Scan Engine for Bluecoat 4.0
Symantec AntiVirus Scan Engine for Bluecoat 4.3
Symantec AntiVirus Scan Engine for Bluecoat 4.3.x
Symantec AntiVirus Scan Engine for Caching 4.3.12
Symantec AntiVirus Scan Engine for Filers 4.3.x
Symantec AntiVirus Scan Engine for ISA 4.3.x
Symantec AntiVirus Scan Engine for Microsoft Portal Server 4.3.x
Symantec AntiVirus Scan Engine for NetApp Filer 4.0
Symantec AntiVirus Scan Engine for NetApp Filer 4.3
Symantec AntiVirus Scan Engine for Netapp Filer 4.3.x
Symantec AntiVirus Scan Engine for NetApp NetCache 4.0
Symantec AntiVirus Scan Engine for NetApp NetCache 4.3
Symantec AntiVirus Scan Engine for Netapp NetCache 4.3.x
Symantec AntiVirus/Filtering for Domino NT 3.1
Symantec AntiVirus/Filtering for Domino Ports 3.0
Symantec AntiVirus/Filtering for Domino Ports 3.0.11
Symantec BrightMail AntiSpam 4.0
Symantec BrightMail AntiSpam 5.5
Symantec BrightMail AntiSpam 6.0
Symantec Client Security 3.x
Symantec Client Security for Nokia
Symantec Gateway Security 1.0
Symantec Gateway Security 5000 Series 3.0
Symantec Gateway Security 5400 Series 2.0
Symantec I-Gear
Symantec Mail Security for Domino 4.0
Symantec Mail Security for Domino 4.1
Symantec Mail Security for Domino NT 4.0
Symantec Mail Security for Domino NT 4.1.4
Symantec Mail Security for Microsoft Exchange 4.0
Symantec Mail Security for Microsoft Exchange 4.5
Symantec Mail Security for Microsoft Exchange 4.6
Symantec Mail Security for Microsoft Exchange 4.6.3
Symantec Mail Security for Microsoft Exchange 5.0
Symantec Mail Security for SMTP 4.0
Symantec Mail Security for SMTP 4.1
Symantec Norton Antivirus 2004
Symantec Norton Antivirus 2005
Symantec Norton Antivirus 2006
Symantec Norton AntiVirus 7.6
Symantec Norton Antivirus for Macintosh 7.x
Symantec Norton Antivirus for Macintosh 8.x
Symantec Norton Antivirus for Macintosh 9.x
Symantec Norton Antivirus for Macintosh Corporate Edition 9.0
Symantec Norton Internet Security for Macintosh 2.x
Symantec Norton Internet Security for Macintosh 3.x
Symantec Norton Internet Security Professional 2004
Symantec Norton Internet Security Professional 2005
Symantec Norton Internet Security Professional 2006
Symantec Norton System Works 2006
Symantec Norton System Works for Macintosh 3.x
Symantec Norton System Works for Macintosh 7.0
Symantec Norton System Works2004
Symantec Norton System Works2005
Symantec Scan Engine 5.0.1 and prior
Symantec Web Security 3.0.1
Symantec Web Security 3.01x
Norton AntiVirus for Microsoft Exchange 2.18
Norton Personal Firewall 2004
Norton Personal Firewall 2005
Norton Personal Firewall 2006
SharePoint Portal Server 2003

Impact

Gain Access

Recommended Actions

Apply the appropriate patch for your system.
http://securityresponse.symantec.com/avcenter/security/Content/2005.12.21b.html

CVE References

CVE-2005-4438