CVE-2007-3771 - CVE House
Back to Database
Status published Medium CVE-2007-3771

Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in...

Vulnerability Description

Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the original vendor advisory referenced CVE-2006-3456, but this was an error.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3771

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

client security, norton antivirus
Vulnerable Versions:
2.0, 3.0, 3.0.1.1000, 3.0.1.1007, 3.0.1.1009, 3.0.2, 3.0.2.2000, 3.0.2.2001, 3.0.2.2002, 3.0.2.2011, 3.0.2.2021, 9.0, 9.0.0.338, 9.0.1, 9.0.1.1.1000, 9.0.1.1000, 9.0.2, 9.0.2.1000, 9.0.3.1000, 9.0.4, 9.0.5, 9.0.5.1100, 10.0, 10.0.1.1000, 10.0.1.1007, 10.0.2.2000, 10.0.2.2001, 10.0.2.2002, 10.0.2.2010, 10.0.2.2011, 10.0.2.2020, 10.0.2.2021

Timeline

Official Publish: July 15th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.