HIGH · 9.3

CVE-2007-0447

Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.

Vulnerability Description

Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecAntivirus Scan Engine4.0
SymantecBrightmail Antispam4.0
SymantecClient Security2.0
SymantecMail Security4.0
SymantecNorton AntivirusAll versions
SymantecNorton Internet Security3.0
SymantecNorton Personal Firewall2006
SymantecNorton System Works3.0
SymantecSymantec Antivirus Filtering \+For Domino3.0.12
SymantecWeb Security2.5
SymantecGateway Security 5000 Series3.0.1
SymantecGateway Security 54002.0.1
SymantecMail Security 8820 ApplianceAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-0447?

CVE-2007-0447 is a vulnerability with a CVSS score of 9.3 (HIGH). Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.

How severe is CVE-2007-0447?

CVE-2007-0447 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0447?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Antivirus Scan Engine, Symantec Brightmail Antispam, Symantec Client Security, Symantec Mail Security, Symantec Norton Antivirus.