Symantec Data Loss Prevention Bugs in KeyView Filter Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1026157 |
|
SecurityTracker URL: http://securitytracker.com/id/1026157
|
|
CVE Reference:
CVE-2011-0337, CVE-2011-0338, CVE-2011-0339, CVE-2011-1213, CVE-2011-1214, CVE-2011-1215, CVE-2011-1216, CVE-2011-1218, CVE-2011-1512
(Links to External Site)
|
Date: Oct 7 2011
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 10.x, 11.x
|
Description:
Multiple vulnerabilities were reported in Symantec Data Loss Prevention. A remote user can cause denial of service conditions on the target system.
A remote user can create a specially crafted file that, when processed by the target filter, will cause a child process to crash.
The vulnerabilities reside in the third party Autonomy Verity Keyview Filter component.
A specially crafted Ichitaro Speed Reader document can trigger this flaw [CVE-2011-0337, CVE-2011-0338, CVE-2011-0339].
A specially crafted Excel file can trigger this flaw [CVE-2011-1213, CVE-2011-1512].
A specially crafted LZH archive can trigger this flaw [CVE-2011-1214].
A specially crafted RTF attachment can trigger this flaw [CVE-2011-1215].
A specially crafted Applix spreadsheet can trigger this flaw [CVE-2011-1216].
A specially crafted Zip File Viewer document can trigger this flaw [CVE-2011-1218].
Binaryhouse.net (via iDefense Labs), CoreLabs Research, Secunia Research, and CERT.org reported these vulnerabilities.
|
Impact:
A remote user can create a file that, when processed by the target filter, will cause partial denial of service conditions.
|
Solution:
The vendor has issued a fix (11.1.1).
The vendor's advisory is available at:
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20111006_00
|
Vendor URL: www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20111006_00 (Links to External Site)
|
Cause:
Access control error, Boundary error
|
Underlying OS:
Linux (Red Hat Enterprise), Windows (2003), Windows (Vista), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 07 Oct 2011 19:52:44 +0000
Subject: Symantec Mail Security / Symantec Brightmail / Symantec Data Loss Prevention
|
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20111006_00
CVE-2011-0337
CVE-2011-0338
CVE-2011-0339
CVE-2011-1213
CVE-2011-1214
CVE-2011-1215
CVE-2011-1216
CVE-2011-1218
CVE-2011-1512
|
|