SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#713620

Symantec Norton AntiVirus vulnerable to DoS via the Auto-Protect "SmartScan" feature

Overview

Symantec Norton AntiVirus may hang or crash when the Auto-Protect module SmartScan feature scans a renamed file on a network share.

I. Description

Symantec Norton AntiVirus is an anti-virus product for desktop and enterprise use. The Norton AntiVirus "Auto-Protect" module provides automatic file scanning and detection of viruses, Trojans, and worms. The Auto-Protect module includes a feature called "SmartScan" which, as an alternative to scanning all file types, only scans specifically targeted file types and extensions. A flaw in the SmartScan feature is triggered when a file residing on a network share is renamed that may cause excessive CPU consumption and an eventual system hang or crash as a result.

II. Impact

A local authenticated user may be able to cause the system to crash or hang by renaming a file residing on a network share.

III. Solution

Apply an update

Symantec has released fixes for this problem that are available through the LiveUpdate functionality of the products. Symantec advisory SYM05-006 provides details on obtaining updates through LiveUpdate or other channels.

Systems Affected

VendorStatusDate NotifiedDate Updated
Symantec CorporationVulnerable30-Mar-2005

References


http://securityresponse.symantec.com/avcenter/security/Content/2005.03.28.html
http://secunia.com/advisories/14741/
http://www.securityfocus.com/bid/12924
http://www.securitytracker.com/alerts/2005/Mar/1013586

Credit

Thanks to Isamu Noguchi, JPCERT, and IPA for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

Date Public:2005-03-28
Date First Published:2005-03-30
Date Last Updated:2005-03-30
CERT Advisory: 
CVE-ID(s):CAN-2005-0923
NVD-ID(s):CAN-2005-0923
US-CERT Technical Alerts: 
Metric:4.05
Document Revision:5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader