Symantec Products CLIproxy.dll ActiveX Control Buffer Overflow
Publish Date: 21 lipca 2015
Severity: : Critical
CVE Kennungen: : CVE-2010-0108
Advisory Date: 21 lipca 2015
DESCRIPTION
Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1004016
Trend Micro Deep Security DPI Rule Name: 1004016 - Symantec Products CLIproxy.dll ActiveX Control Buffer Overflow
AFFECTED SOFTWARE AND VERSION:
- symantec antivirus 10.0
- symantec antivirus 10.0.1
- symantec antivirus 10.0.1.1
- symantec antivirus 10.0.2
- symantec antivirus 10.0.2.1
- symantec antivirus 10.0.2.2
- symantec antivirus 10.0.3
- symantec antivirus 10.0.4
- symantec antivirus 10.0.5
- symantec antivirus 10.0.6
- symantec antivirus 10.0.7
- symantec antivirus 10.0.8
- symantec antivirus 10.0.9
- symantec antivirus 10.1
- symantec antivirus 10.1.0.1
- symantec antivirus 10.1.4
- symantec antivirus 10.1.4.1
- symantec antivirus 10.1.5
- symantec antivirus 10.1.5.1
- symantec antivirus 10.1.6
- symantec antivirus 10.1.6.1
- symantec antivirus 10.1.7
- symantec antivirus 10.2
- symantec client_security 3.0
- symantec client_security 3.0.0.359
- symantec client_security 3.0.1.1000
- symantec client_security 3.0.1.1007
- symantec client_security 3.0.1.1008
- symantec client_security 3.0.2
- symantec client_security 3.0.2.2000
- symantec client_security 3.0.2.2001
- symantec client_security 3.0.2.2010
- symantec client_security 3.0.2.2011
- symantec client_security 3.0.2.2020
- symantec client_security 3.0.2.2021
- symantec client_security 3.1
- symantec client_security 3.1.0.396
- symantec client_security 3.1.0.401
- symantec client_security 3.1.394
- symantec client_security 3.1.400
- symantec client_security 3.1.401
- symantec endpoint_protection 11