copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2004.0228 -- Two NGSSoftware Insight Security Research Advisories -- ActiveX Vulnerabilities in Norton (Symantec) Client Security Products

Date: 23 March 2004
References: ESB-2004.0229  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
             AUSCERT External Security Bulletin Redistribution

   ESB-2004.0228 -- Two NGSSoftware Insight Security Research Advisories
   ActiveX Vulnerabilities in Norton (Symantec) Client Security Products
                               23 March 2004

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:                Norton Internet Security
                        Norton AntiSpam
Publisher:              NGSSoftware
Operating System:       Windows XP
Impact:                 Execute Arbitrary Code/Commands
Access Required:        Remote

Comment: NGSSoftware Advisory Numbers:
                        #NISR19042004b
                        #NISR19042004a

- --------------------------BEGIN INCLUDED TEXT--------------------

NGSSoftware Insight Security Research Advisory

Name: Norton Internet Security Remote Command Execution
Systems Affected: XP (not confirmed on 2000); NIS & NIS Pro 2004, not
confirmed on previous versions.
Severity: High
Vendor URL: http://www.symantec.com
Author: Mark Litchfield [ mark@ngssoftware.com ]
Date Vendor Notified:    4th March 2004
Date of Public Advisory: 19th March 2004
Advisory number: #NISR19042004b
Advisory URL: http://www.ngssoftware.com/advisories/nisrce.txt

Description
***********

Symantec's Norton Internet Security 2004 Professional protects you and
your business from online threats. It eliminates viruses automatically,
blocks hackers, safeguards your personal information, fights spam, increases
online productivity, recovers lost or damaged files, and thoroughly deletes
confidential data you no longer need.


Details
*******

Installed with Norton Internet Security and Professional is an ActiveX
component that is marked safe for scripting, namely WrapNISUM Class
(c:\program files\Norton Internet Security Professional\WrapUM.dll).
Using the LaunchURL method an attacker has the ability to force the browser
to run arbitrary executables on the target.  In a real world attack, this
would more than likely take the form of a UNC path.  It's important to note
here that on those windows operating systems that support the WEBDAV
redirector file system if the UNC path cannot be reached over TCP port 139
or 445 it will switch to TCP Port 80 (http).  Needless to say this aspect
will allow attacks to go through corporate firewalls.  The attack can be
achieved either by encouraging the 'victim' to visit a malicious web page or
placing a script within the content of an (html) email.


Fix Information
***************

Shipped with all Symantec's products is the LiveUpdate feature. Open
Internet Security / Professional and select the LiveUpdate feature which
will retrieve the lastest patch.  It's worth mentioning Symantec's quick
response to this issue in ensuring their clients remain protected.

About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com


NGSSoftware Insight Security Research Advisory

Name: Norton AntiSpam Remote Buffer Overrun
Systems Affected: Windows XP (not confirmed on 2000)
Severity: High
Vendor URL: http://www.symantec.com
Author: Mark Litchfield [ mark@ngssoftware.com ]
Date Vendor Notified:    4th March 2004
Date of Public Advisory: 19th March 2004
Advisory number: #NISR19042004a
Advisory URL: http://www.ngssoftware.com/advisories/antispam.txt

Description
***********

Symantec's Norton AntiSpamT 2004 filters unwanted email out of your inbox.
Working with any POP3 email program, it filters incoming mail on multiple
levels, detecting and flagging unsolicited messages while promptly
delivering valid mail. To make your online time more enjoyable, Norton
AntiSpam also blocks intrusive pop-up and banner ads.
It is worth mentioning here, that Norton AntiSpamT is also packaged within
Norton Internet Security 2004 and Norton Internet Security 2004
Professional.

Details
*******

Installed with Norton AntiSpam is an ActiveX component that is marked safe
for scripting, namely SymSpamHelper Class (c:\program files\common
files\symantec shared\antispam\symspam.dll).
Using the method LaunchCustomRuleWizard with an overly long parameter, an
attacker can cause a stack based overflow allowing the ability to remotley
run arbitrary code on the target.  This can be achieved either by
encouraging the 'victim' to visit a malicious web page or placing a script
within the content of an (html) email.


Fix Information
***************

Shipped with all Symantecs products is the LiveUpdate feature. Open Norton
AntiSpam or Norton Internet Security / Professional and select the
LiveUpdate feature which will retrieve the lastest patch.  Also worth
mentioning is Symantec's quick response to this issue in ensuring their
clients remain protected.

About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business 
                hours which are GMT+10:00 (AEST).  On call after hours 
                for member emergencies only.

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBQGAkACh9+71yA2DNAQFSTgP+O4vos0tjpgTExsg/P+Dz6yPjyOPGsapT
v/nXGUsMqrLVoTVUDqiU1owCqqn5HlPdN0VwWm6XD7XKL+1780Xr6I1tMXl++fzz
TqTz3ik9XYPEieL8lhRJ/IXLVeuzg5SAJ2noLv8UPkyh72lLsOIcd6dUzZRhQ1l3
+RWh9+pZWFA=
=ztDF
-----END PGP SIGNATURE-----