Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DNS:OVERFLOW:SYMNTEC-CNAME

Severity

High

Recommended

No

Recommended Action

Drop

Category

DNS

Keywords

Symantec DNS CNAME Buffer Overflow (1)

Release Date

2015/06/12

Update Number

2504

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DNS: Symantec DNS CNAME Buffer Overflow (1)


This signature detects attempts to exploit a known vulnerability in Symantec Firewall clients. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the vulnerable application.

Extended Description

Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.

Affected Products

  • symantec client_firewall 5.01
  • symantec client_firewall 5.1.1
  • symantec client_security 1.0
  • symantec client_security 1.1
  • symantec client_security 1.2
  • symantec client_security 1.3
  • symantec client_security 1.4
  • symantec client_security 1.5
  • symantec client_security 1.6
  • symantec client_security 1.7
  • symantec client_security 1.8
  • symantec client_security 1.9
  • symantec client_security 2.0
  • symantec norton_antispam 2004
  • symantec norton_internet_security 2002
  • symantec norton_internet_security 2002 (:pro)
  • symantec norton_internet_security 2003
  • symantec norton_internet_security 2003 (:pro)
  • symantec norton_internet_security 2004
  • symantec norton_internet_security 2004 (:pro)
  • symantec norton_personal_firewall 2002
  • symantec norton_personal_firewall 2003
  • symantec norton_personal_firewall 2004

References

  • CVE: CVE-2004-0444

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out