PCZONE 討論區

PCZONE 討論區 (https://www.pczone.com.tw/vbb3/)
-   -- 防 駭 / 防 毒 版 (https://www.pczone.com.tw/vbb3/forum/28/)
-   -   Norton Anti-Virus 的 bug (https://www.pczone.com.tw/vbb3/thread/28/92185/)

sic 2004-03-10 06:47 PM

Norton Anti-Virus 的 bug
 
[url]http://securitytracker.com/alerts/2004/Mar/1009333.html[/url]

Symantec's Norton Anti-Virus Fails to Scan Files With Certain Characters in Path Names

SecurityTracker Alert ID: 1009333
CVE Reference: GENERIC-MAP-NOMATCH (Links to External Site)
Date: Mar 5 2004

Impact: Denial of service via local system

Exploit Included: Yes

Version(s): 2002; version 8.00.58; possibly others

Description: A vulnerability was reported in Symantec's Norton Anti-Virus. A local user or a virus may create a file or directory that cannot be scanned by the anti-virus engine.

Bipin Gautam ( hUNT3R ) reported that the software will crash when performing a manual scan of a file or folder with a name containing certain ASCII characters. The report indicates that ASCII characters 1 - 31 can be used in a folder or filename to trigger the flaw. For example, a folder named '!' can be used. When Norton Anti-Virus attempts to scan the folder manually, 'NAVW32.exe' will crash, the report said.

The Auto-Protect feature is not affected, the report said.

A demonstration exploit is available at:

[url]http://www.geocities.com/visitbipin/t[/url] est_nav.zip

Impact: A local user (or virus code) can create a file with a particular type of file path name that will not be scanned manually by the anti-virus scanning engine.

Solution: No solution was available at the time of this entry.

Vendor URL: [url]www.symantec.com/[/url] (Links to External Site)

Cause: State error

Underlying OS: Windows (Any)

Reported By: "Bipin Gautam." <[email protected]>

Message History: None.


所有時間均為 +8。現在的時間是 08:11 AM



 XML   RSS 2.0   RSS 
本站使用 vBulletin 合法版權程式
站務信箱 : [email protected]

本論壇所有文章僅代表留言者個人意見,並不代表本站之立場,討論區以「即時留言」方式運作,故無法完全監察所有即時留言,若您發現文章可能有異議,請 email :[email protected] 處理。