Buffer Overflow in Symantec AntiVirus Scan Engine Administrative Interface
CVE-2005-2758

Currently unrated

Key Information:

Summary

An integer signedness error exists in the administrative interface of the Symantec AntiVirus Scan Engine versions 4.0 and 4.3, which can be exploited by attackers. This vulnerability allows for crafted HTTP headers with negative values, leading to a heap-based buffer overflow that enables remote attackers to execute arbitrary code on the affected systems.

References

EPSS Score

21% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.