| Vulnerability Name: | CVE-2002-1777 (CCN-8392) | ||||||||
| Assigned: | 2002-03-07 | ||||||||
| Published: | 2002-03-07 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | ** DISPUTED ** Note: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. Note: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Thu Mar 07 2002 - 11:16:01 CST Various Vulnerabilities in Norton Anti-Virus 2002 Source: CCN Type: BugTraq Mailing List, Fri Mar 08 2002 - 14:16:02 CST Re: Edvice Security Services Source: MITRE Type: CNA CVE-2002-1777 Source: BUGTRAQ Type: UNKNOWN 20020307 Various Vulnerabilities in Norton Anti-Virus 2002 Source: BUGTRAQ Type: UNKNOWN 20020308 Re: Edvice Security Services Source: BID Type: UNKNOWN 4246 Source: CCN Type: BID-4246 Symantec Norton AntiVirus Conflicting MIME Header Vulnerability Source: XF Type: UNKNOWN nav-contenttype-bypass-protection(8392) Source: XF Type: UNKNOWN nav-contenttype-bypass-protection(8392) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||