Description
Vulnerabilities have been
discovered in two ActiveX controls
used by Norton AntiVirus, Norton Internet
Security, and Norton System Works.
The vulnerabilities are caused due
to errors in the AxSysListView32 and
AxSysListView32OAA ActiveX controls
(NavComUI.dll) when handling malformed "AnomalyList" and "Anomaly" properties
respectively. This error could allow
an attacker to crash Internet Explorer,
or possibly run arbitrary code with
the rights of the logged in user.
Product
affected
Norton AntiVirus 2006
Norton Internet Security 2006
Norton Internet Security, Anti Spyware Edition 2005
Norton System Works 2006
Solution
Run LiveUpdate
in Interactive Mode for download the latest virus definitions and
IPS signatures dated 08-09-2007 and later
Suggested
Solutions
Intrusion
Prevention System: 3Com
Tippingpoint, McAfee
IntruShield
EndPoint Protection: Symantec Sygate
Enterprise Protection
Source
Symantec
|