Symantec Data Loss Prevention Buffer Overflow in KeyView Filter Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1025596 |
|
SecurityTracker URL: http://securitytracker.com/id/1025596
|
|
CVE Reference:
CVE-2011-0548
(Links to External Site)
|
Date: Jun 2 2011
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 10.x, 11.x
|
Description:
A vulnerability was reported in Symantec Data Loss Prevention. A remote user can cause denial of service conditions.
A remote user can send a specially crafted Lotus Freelance Graphics PRZ file to cause partial denial of service conditions.
The vulnerability resides in the Autonomy Verity KeyView Filter component.
The following versions are affected:
Symantec Data Loss Prevention Enforce/Detection Servers for Windows 10.x and prior
Symantec Data Loss Prevention Enforce/Detection Servers for Linux 10.x and prior
Symantec Data Loss Prevention Endpoint Agents 10.x and prior
Symantec Data Loss Prevention Enforce/Detection Servers for Windows 11.x
Symantec Data Loss Prevention Enforce/Detection Servers for Linux 11.x
Symantec Data Loss Prevention Endpoint Agents 11.x
alino from binaryhouse.net reported this vulnerability via iDefense.
|
Impact:
A remote user can cause denial of service conditions.
|
Solution:
The vendor has issued a fix (Symantec_DLP_10.5.3_ReleaseUpdate_Win-IN.zip for DLP 10.5 for Windows, Symantec_DLP_10.5.3_ReleaseUpdate_Lin-IN.zip for DLP 10.5 for Linux, Symantec_DLP_10.5.3_Agent_Win-IN.zip for DLP Agent 10.5, DLP 11.1).
The vendor's advisory is available at:
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110531_00
|
Vendor URL: www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110531_00 (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
Linux (Red Hat Enterprise), Windows (2003), Windows (Vista), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 02 Jun 2011 06:21:55 +0000
Subject: Symantec Data Loss Prevention
|
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110531_00
CVE-2011-0548
|
|