Search

published date: December 31, 2004

CVE-2004-2147 : Denial of Service Vulnerability

Description

Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.

Product(s):

  • Symantec Norton Antivirus 2.1 for MS Exchange
  • Symantec Norton Antivirus 2001
  • Symantec Norton Antivirus 2002
  • Symantec Norton Antivirus 2003
  • Symantec Norton Antivirus Corporate 7.0
  • Symantec Norton Antivirus Corporate 7.2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-2147, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-2147 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?