CVE-2005-0249

UnknownEPSS 18.83%

Last modified

CVE-2005-0249 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.. EPSS estimates a 18.83% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.

Metrics

EPSS Probability
18.83%

96.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
SymantecAntivirus Scan Engine< 4.3.3—
SymantecBrightmail Antispam4.0—
SymantecBrightmail Antispam5.5—
SymantecClient Security1.0.1_build_8.01.434Mr3
SymantecClient Security1.0.1_build_8.01.437—
SymantecClient Security1.0.1_build_8.01.446Mr4
SymantecClient Security1.0.1_build_8.01.457Mr5
SymantecClient Security1.0.1_build_8.01.460Mr6
SymantecClient Security1.0.1_build_8.01.464Mr7
SymantecClient Security1.0.1_build_8.01.471Mr8
SymantecClient Security1.1.1_mr1_build_8.1.1.314a—
SymantecClient Security1.1.1_mr2_build_8.1.1.319—
SymantecClient Security1.1.1_mr3_build_8.1.1.323—
SymantecClient Security1.1.1_mr4_build_8.1.1.329—
SymantecClient Security1.1.1_mr5_build_8.1.1.336—
SymantecGateway Security1.0—
SymantecGateway Security2.0—
SymantecGateway Security2.0.1—
SymantecMail Security4.0—
SymantecMail Security4.1Build 458
SymantecMail Security4.5_build_719—
SymantecNorton Antivirus2.18_build_83—
SymantecNorton Antivirus8.1.1.319—
SymantecNorton Antivirus8.1.1.323—
SymantecNorton Antivirus8.1.1.329—
SymantecNorton Antivirus8.1.1_build8.1.1.314a—
SymantecNorton Antivirus8.01.434—
SymantecNorton Antivirus8.01.437—
SymantecNorton Antivirus8.01.446—
SymantecNorton Antivirus8.01.457—
SymantecNorton Antivirus8.01.460—
SymantecNorton Antivirus8.01.464—
SymantecNorton Antivirus8.01.471—
SymantecNorton Antivirus9.0—
SymantecNorton Antivirus2004—
SymantecNorton Internet Security2004—
SymantecNorton System Works2004—
SymantecSav Filter Domino Nt Portsbuild3.0.5—
SymantecSav Filter For Domino Nt3.1.1—
SymantecWeb Security3.01.59—
SymantecWeb Security3.01.60—
SymantecWeb Security3.01.61—
SymantecWeb Security3.01.62—
SymantecWeb Security3.01.63—
SymantecWeb Security3.01.67—
SymantecWeb Security3.01.68—

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-0249?
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
How severe is CVE-2005-0249?
Severity scoring for CVE-2005-0249 is pending analysis. The EPSS model estimates a 18.83% probability of exploitation in the next 30 days.
How do I fix CVE-2005-0249?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2005

Are you affected by CVE-2005-0249?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST