Buffer Overflow in Symantec AntiVirus Scan Engine Administrative Interface
CVE-2005-2758
Currently unrated
Key Information:
- Vendor
- Symantec
- Vendor
- CVE Published:
- 5 October 2005
Summary
An integer signedness error exists in the administrative interface of the Symantec AntiVirus Scan Engine versions 4.0 and 4.3, which can be exploited by attackers. This vulnerability allows for crafted HTTP headers with negative values, leading to a heap-based buffer overflow that enables remote attackers to execute arbitrary code on the affected systems.
References
EPSS Score
21% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved