Vulnerability of Symantec AV: format string attack

Synthesis of the vulnerability 

An attacker can use the customizing of alert notification message to run code on the machine or generate a denial of service.
Vulnerable systems: Symantec AV, SWS.
Severity of this threat: 2/4.
Creation date: 14/09/2006.
Références of this weakness: CERTA-2006-AVI-394, CVE-2006-3454, SYM06-017, VIGILANCE-VUL-6158.

Description of the vulnerability 

The Symantec antivirus software permits the user to customize the alert notification message when a virus is detected.

Two format string attacks have been identified in the customizing of alert notification:
  - the input parameters are not correctly checked, which permits to generate a format string attack during the customizing of the message,
  - the contain of the message is not correctly sanitized, and can lead to a denial of service via a format string attack when e malicious file is detected.
This threat alert impacts software or systems such as Symantec AV, SWS.

Our Vigil@nce team determined that the severity of this computer vulnerability bulletin is medium.

The trust level is of type confirmed by the editor, with an origin of user shell.

An attacker with a expert ability can exploit this weakness note.

Solutions for this threat 

Symantec AV: patch.
A patch is available:
