vendor:
Norton AntiVirus
by:
Bipin Gautam
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: Norton AntiVirus
Affected Version From: Symantec Norton AntiVirus 2003 Professional Edition
Affected Version To: Symantec Norton AntiVirus 2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
Norton AntiVirus Denial Of Service Vulnerability
While scanning specially crafted compressed files, Norton AntiVirus triggers a Denial of Service (DoS) attack by using 100% CPU for a long time. The scan cannot be stopped manually, forcing the user to kill the process. A proof of concept file is provided to demonstrate the vulnerability. Other antivirus or trojan scanners may also be vulnerable.
Mitigation:
No mitigation or remediation information provided