Back to Database
Status published
Critical
CVE-2007-3699
The Decomposer component in multiple Symantec products allows remote attackers...
Vulnerability Description
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3699
Credits & Attribution
No credits recorded in the NVD database.
References
More from symantec
View All →CVE-2017-13679
A denial of service (DoS) attack in Symantec Encryption Desktop...
Medium
4.2
CVE-2017-13675
A denial of service (DoS) attack in Symantec Endpoint Encryption...
Medium
4.2
CVE-2016-5313
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users...
High
8.8
CVE-2016-5312
Directory traversal vulnerability in the charting component in Symantec Messaging...
Medium
6.5
CVE-2016-5308
The Client Intrusion Detection System (CIDS) driver before 15.0.6 in...
Medium
5.5
Affected Vendor
symantec
View all reports →Affected Software
antivirus scan engine, brightmail antispam, client security, mail security, norton antivirus, norton internet security, norton personal firewall, norton system works, symantec antivirus filtering \+for domino, web security, gateway security 5000 series, gateway security 5400, mail security 8820 appliance
Vulnerable Versions:
4.0, 4.1, 4.1.8, 4.3, 4.3.3, 4.3.7.27, 4.3.8.29, 4.3.12, 5.0, 5.0.1, 5.5, 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 2.0, 2.0.1_build_9.0.1.1000, 2.0.2_build_9.0.2.1000, 2.0.3_build_9.0.3.1000, 2.0.4, 2.0.5_build_1100_mp1, 2.0.6, 3.0, 3.0.0.359, 3.0.1.1000, 3.0.1.1001, 3.0.1.1007, 3.0.1.1008, 3.0.2.2000, 3.0.2.2001, 3.0.2.2002, 3.0.2.2010, 3.0.2.2011, 3.0.2.2020, 3.0.2.2021, 3.1, 3.1.394, 3.1.396, 3.1.400, 3.1.401, 4.0.1, 4.5, 4.5.4.743, 4.5_build_719, 4.5_build_736, 4.5_build_741, 4.6.1.107, 4.6.3, 4.6_build_97, 5.0.0.204, 5.1.0, 6.0.0, 9.0, 9.0.0, 9.0.0.338, 9.0.1, 9.0.1.1.1000, 9.0.2, 9.0.2.1000, 9.0.3, 9.0.3.1000, 9.0.4, 9.0.5, 9.0.5.1100, 9.0.6.1000, 10.0, 10.0.0, 10.0.0.359, 10.0.1, 10.0.1.1000, 10.0.1.1007, 10.0.1.1008, 10.0.2.2000, 10.0.2.2001, 10.0.2.2002, 10.0.2.2010, 10.0.2.2011, 10.0.2.2020, 10.0.2.2021, 10.1, 10.1.4, 10.1.4.4010, 10.1.394, 10.1.396, 10.1.400, 10.1.401, 10.9.1, 2004, 2005, 2006, 2006_9.1.0.33, 2006_9.1.1.7, 3.0.12, 2.5, 3.0.1, 3.0.1.70, 3.0.1.76, 3.0.1_build_3.01.70, 3.0.1_build_3.01.72, 3.0.1_build_3.01.74, 3.01.59, 3.01.60, 3.01.61, 3.01.62, 3.01.63, 3.01.67, 3.01.68, 2.0.1
Timeline
Official Publish:
October 5th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.