vendor:
Norton Internet Security
by:
MC
7.5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Norton Internet Security
Affected Version From: Symantec Norton Internet Security 2004
Affected Version To: Symantec Norton Internet Security 2004
Patch Exists: NO
Related CWE: CVE-2007-1689
CPE: a:symantec:norton_internet_security:2004
Platforms Tested: Windows XP SP0/SP1 Pro English, Windows 2000 Pro English All
2007
Symantec Norton Internet Security 2004 ActiveX Control Buffer Overflow
This module exploits a stack buffer overflow in the ISAlertDataCOM ActiveX Control (ISLAert.dll) provided by Symantec Norton Internet Security 2004. By sending a overly long string to the "Get()" method, an attacker may be able to execute arbitrary code.
Mitigation:
Update to a patched version of Symantec Norton Internet Security 2004.