ID

VAR-200212-0448


CVE

CVE-2002-1777


TITLE

Symantec Norton AntiVirus Inconsistent exception handling MIME Head hole

Trust: 0.6

sources: CNNVD: CNNVD-200212-110

DESCRIPTION

NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to obtain the file name. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but Norton AntiVirus or the Office plug-in would detect the virus before it is executed. An issue has been discovered which involves Symantec Norton AntiVirus 2002 incoming email scanning protection feature. Using conflicting MIME headers, it is possible to rename a file to an excluded filetype in the Content-Type field, and include the original filename in the Content-Disposition field, resulting in the execution of the file by the appropriate application. For example: Content-Type: application/msword;name=\filename.nch Content-Transfer-Encoding: base64 Content-Disposition: attachment;filename=\filename.doc Norton will detect the attachment as a .nch file, however Microsoft Office will detect the .doc extension and handle it as such. If the .doc attachment happens to be a Word macro virus, it will execute on the user's sytem

Trust: 1.26

sources: NVD: CVE-2002-1777 // BID: 4246 // VULHUB: VHN-6160

AFFECTED PRODUCTS

vendor:symantecmodel:norton antivirusscope:eqversion:2002

Trust: 1.6

vendor:symantecmodel:norton antivirusscope:eqversion:20020

Trust: 0.3

sources: BID: 4246 // CNNVD: CNNVD-200212-110 // NVD: CVE-2002-1777

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1777
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200212-110
value: HIGH

Trust: 0.6

VULHUB: VHN-6160
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-1777
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-6160
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-6160 // CNNVD: CNNVD-200212-110 // NVD: CVE-2002-1777

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1777

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200212-110

TYPE

Design Error

Trust: 0.9

sources: BID: 4246 // CNNVD: CNNVD-200212-110

EXTERNAL IDS

db:BIDid:4246

Trust: 2.0

db:NVDid:CVE-2002-1777

Trust: 1.7

db:CNNVDid:CNNVD-200212-110

Trust: 0.7

db:NSFOCUSid:2364

Trust: 0.6

db:XFid:8392

Trust: 0.6

db:VULHUBid:VHN-6160

Trust: 0.1

sources: VULHUB: VHN-6160 // BID: 4246 // CNNVD: CNNVD-200212-110 // NVD: CVE-2002-1777

REFERENCES

url:http://www.securityfocus.com/bid/4246

Trust: 2.7

url:http://online.securityfocus.com/archive/1/260271

Trust: 2.1

url:http://online.securityfocus.com/archive/1/260678

Trust: 2.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/8392

Trust: 2.1

url:http://xforce.iss.net/xforce/xfdb/8392

Trust: 0.6

url:http://www.nsfocus.net/vulndb/2364

Trust: 0.6

url:http://www.symantec.com/nav/nav_9xnt/

Trust: 0.3

url:http://www.symantec.com

Trust: 0.3

sources: VULHUB: VHN-6160 // BID: 4246 // CNNVD: CNNVD-200212-110 // NVD: CVE-2002-1777

CREDITS

Edvice Security Services※ support@edvicesecurity.com

Trust: 0.6

sources: CNNVD: CNNVD-200212-110

SOURCES

db:VULHUBid:VHN-6160
db:BIDid:4246
db:CNNVDid:CNNVD-200212-110
db:NVDid:CVE-2002-1777

LAST UPDATE DATE

2024-11-22T23:13:03.687000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-6160date:2017-07-11T00:00:00
db:BIDid:4246date:2002-03-07T00:00:00
db:CNNVDid:CNNVD-200212-110date:2005-10-20T00:00:00
db:NVDid:CVE-2002-1777date:2024-11-20T23:42:06.117

SOURCES RELEASE DATE

db:VULHUBid:VHN-6160date:2002-12-31T00:00:00
db:BIDid:4246date:2002-03-07T00:00:00
db:CNNVDid:CNNVD-200212-110date:2002-03-07T00:00:00
db:NVDid:CVE-2002-1777date:2002-12-31T05:00:00