Vulnerability CVE-2006-6490


Published: 2007-02-22   Modified: 2012-02-12

Description:
Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Symantec -> Automated support assistant 
Symantec -> Norton antivirus 
Symantec -> Norton internet security 
Symantec -> Norton system works 
Supportsoft -> Scriptrunner 
Supportsoft -> Smartissue 

 References:
http://archives.neohapsis.com/archives/bugtraq/2007-02/0454.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=478
http://www.kb.cert.org/vuls/id/441785
http://www.securityfocus.com/archive/1/461147/100/0/threaded
http://www.securityfocus.com/bid/22564
http://www.securitytracker.com/id?1017688
http://www.securitytracker.com/id?1017689
http://www.securitytracker.com/id?1017690
http://www.securitytracker.com/id?1017691
http://www.symantec.com/avcenter/security/Content/2007.02.22.html
http://www.vupen.com/english/advisories/2007/0703
http://www.vupen.com/english/advisories/2007/0704
https://exchange.xforce.ibmcloud.com/vulnerabilities/32636

Copyright 2021, cxsecurity.com

 

Back to Top