HIGH · 9.3

CVE-2007-3699

The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.

Vulnerability Description

The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecAntivirus Scan Engine4.0
SymantecBrightmail Antispam4.0
SymantecClient Security2.0
SymantecMail Security4.0
SymantecNorton AntivirusAll versions
SymantecNorton Internet Security3.0
SymantecNorton Personal Firewall2006
SymantecNorton System Works3.0
SymantecSymantec Antivirus Filtering \+For Domino3.0.12
SymantecWeb Security2.5
SymantecGateway Security 5000 Series3.0.1
SymantecGateway Security 54002.0.1
SymantecMail Security 8820 ApplianceAll versions

References

FAQ

What is CVE-2007-3699?

CVE-2007-3699 is a vulnerability with a CVSS score of 9.3 (HIGH). The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.

How severe is CVE-2007-3699?

CVE-2007-3699 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3699?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Antivirus Scan Engine, Symantec Brightmail Antispam, Symantec Client Security, Symantec Mail Security, Symantec Norton Antivirus.