Description
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
Affected products
- Symantec / norton_antispam2004 – 2004
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=107980262324362&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/11169
- VENDOR_ADVISORYhttp://www.nextgenss.com/advisories/antispam.txt
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/15536
- MAILING_LISThttp://marc.info/?l=bugtraq&m=107970870606638&w=2
- MISChttp://www.kb.cert.org/vuls/id/344718
- MISChttp://www.securityfocus.com/bid/9916
- MISChttp://www.sarc.com/avcenter/security/Content/2004.03.19.html