Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: Norton AntiVirus Scanner Remote Denial Of ServiceVulnerability [Part: !!!]
From: Matt Cuttler <mcuttler () bnl gov>
Date: Mon, 12 Jul 2004 14:07:00 -0400

clamav has options such as:
--max-files --max-space --max-recursion and --max-ratio
..which will protect against these types of DOS attacks.

-Matt Cuttler

Richard Massa wrote:

exploit does not crash SAV corporate edition, Scan engine
Scan of file completes successfully.

On Fri, Jul 09, 2004 at 08:55:45PM -0700, bipin gautam wrote:
--- "Peter B. Harvey (Information Security)"
<peterharvey () emergency qld gov au> wrote:
Could you please password protect it and email it to
me. Ill test on Trend Micro.

dust download the file and hit scan, watch out You AV
can trigger a DoS autometically.

It has been confirmed Norton 2004 uses 100% cpu for a
indefinate amount of time. (Tested in 3 Ghz processor)

Please read updates in this advisory at:


and test the exploit with some other AV scanners!


Do you Yahoo!?
Yahoo! Mail - 50x more storage than other providers!

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]