List Info

Thread: PCWorks: Symantec AntiVirus & other Products Alert Notification Two Vulnerabilities




PCWorks: Symantec AntiVirus & other Products Alert Notification Two Vulnerabilities
user name
2006-09-14 12:25:50
TITLE:
Symantec Products Alert Notification Two Vulnerabilities

SECUNIA ADVISORY ID:
SA21884

VERIFY ADVISORY:
http://secunia.c
om/advisories/21884/

CRITICAL:
Less critical

IMPACT:
Privilege escalation, DoS

WHERE:
Local system

SOFTWARE:
Symantec Client Security 3.x
http://secunia.com/p
roduct/6649/
Symantec Client Security 2.x
http://secunia.com/p
roduct/3478/
Symantec Client Security 1.x
http://secunia.com/p
roduct/2344/
Symantec AntiVirus Corporate Edition 9.x
http://secunia.com/p
roduct/3549/
Symantec AntiVirus Corporate Edition 8.x
http://secunia.com/pr
oduct/659/
Symantec AntiVirus Corporate Edition 10.x
http://secunia.com/p
roduct/5555/

DESCRIPTION:
Some vulnerabilities have been reported in Symantec Client 
Security
and Symantec AntiVirus Corporate Edition, which can be 
exploited by
malicious, local users to cause a DoS (Denial of Service) or

gain
escalated privileges.

1) A format string error within the handling of
"Tamper 
Protection"
and "Virus Alert Notification" messages can be
exploited to 
execute
arbitrary code with escalated privileges by replacing the 
message
with a specially crafted format string.

2) Another format string error exists in the alert
notification
process when displaying a notification message upon
detection 
of a
malicious file. This can be exploited to crash the Real Time

Virus
Scan service by replacing the message with a specially
crafted 
format
string.

SOLUTION:
Apply patches (see patch matrix in vendor advisory).

ORIGINAL ADVISORY:
Symantec:
http://securityresponse.symantec.c
om/avcenter/security/Content/2006.09.13.html

Layered Defense:
http://layer
eddefense.com/SAV13SEPT.html
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/r
ules.htm
Contact list owner <owner-pcworksimagicomm.com>
Unsubscribing and other changes: http://pcworkers.com
=====================================================
Array
user name
1969-12-31 18:00:00
Il giorno gio, 14/09/2006 alle 21.25 +1200, Hamish ha
scritto:
> use r.in.gdal:
>   http://www.gdal.
org/frmt_Idrisi.html
> 
> 
> To check to see if it's built in to your copy of GDAL:
> 
> $ gdalinfo --formats

Thanks Hamish,
r.in.gdal did the job well. I'm still stuck with the vector
files which
are in VCT format that OGR doesn't seem to handle.

All the best,
Stefano

-- 
Stefano Costa
http://www.iosa.it Software
Open Source per l'Archeologia
Jabber: stekojabber.linux.it
GnuPG Key ID 1024D/0xD0D30245
Linux Registered User #385969 counter.li.org

_______________________________________________
grassuser mailing list
grassusergrass.itc.it
http:/
/grass.itc.it/mailman/listinfo/grassuser
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )