ID

VAR-201006-0376


CVE

CVE-2010-2305


TITLE

Symantec Sygate Personal Firewall For SSHelper.dll Vulnerable to buffer overflow

Trust: 0.8

sources: JVNDB: JVNDB-2010-005531

DESCRIPTION

Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method. Sygate Personal Firewall ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data. Failed exploit attempts will likely result in denial-of-service conditions. Sygate Personal Firewall 5.6 build 2808 is vulnerable; other versions may also be affected

Trust: 1.98

sources: NVD: CVE-2010-2305 // JVNDB: JVNDB-2010-005531 // BID: 40960 // VULHUB: VHN-44910

AFFECTED PRODUCTS

vendor:symantecmodel:sygate personal firewallscope:eqversion:5.6

Trust: 1.6

vendor:symantecmodel:sygate personal firewallscope:eqversion:5.6 build 2808

Trust: 0.8

vendor:symantecmodel:sygate personal firewall buildscope:eqversion:5.62808

Trust: 0.3

sources: BID: 40960 // JVNDB: JVNDB-2010-005531 // CNNVD: CNNVD-201006-271 // NVD: CVE-2010-2305

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-2305
value: HIGH

Trust: 1.0

NVD: CVE-2010-2305
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201006-271
value: CRITICAL

Trust: 0.6

VULHUB: VHN-44910
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2010-2305
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-44910
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-44910 // JVNDB: JVNDB-2010-005531 // CNNVD: CNNVD-201006-271 // NVD: CVE-2010-2305

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-44910 // JVNDB: JVNDB-2010-005531 // NVD: CVE-2010-2305

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201006-271

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201006-271

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-005531

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-44910

PATCH

title:Sygate Personal Firewallurl:http://www.symantec.com/about/profile/development/acquisitions/detail.jsp?id=sygate

Trust: 0.8

sources: JVNDB: JVNDB-2010-005531

EXTERNAL IDS

db:NVDid:CVE-2010-2305

Trust: 2.8

db:EXPLOIT-DBid:13834

Trust: 1.7

db:OSVDBid:65539

Trust: 1.1

db:JVNDBid:JVNDB-2010-005531

Trust: 0.8

db:CNNVDid:CNNVD-201006-271

Trust: 0.7

db:XFid:59408

Trust: 0.6

db:BIDid:40960

Trust: 0.4

db:SEEBUGid:SSVID-69002

Trust: 0.1

db:VULHUBid:VHN-44910

Trust: 0.1

sources: VULHUB: VHN-44910 // BID: 40960 // JVNDB: JVNDB-2010-005531 // CNNVD: CNNVD-201006-271 // NVD: CVE-2010-2305

REFERENCES

url:http://www.exploit-db.com/exploits/13834

Trust: 1.7

url:http://www.corelan.be:8800/index.php/forum/security-advisories/10-050-sygate-personal-firewall-5-6-build-2808-activex/

Trust: 1.7

url:http://osvdb.org/65539

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/59408

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-2305

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-2305

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/59408

Trust: 0.6

url:http://www.symantec.com/norton/sygate/index.jsp

Trust: 0.3

sources: VULHUB: VHN-44910 // BID: 40960 // JVNDB: JVNDB-2010-005531 // CNNVD: CNNVD-201006-271 // NVD: CVE-2010-2305

CREDITS

Lincoln

Trust: 0.3

sources: BID: 40960

SOURCES

db:VULHUBid:VHN-44910
db:BIDid:40960
db:JVNDBid:JVNDB-2010-005531
db:CNNVDid:CNNVD-201006-271
db:NVDid:CVE-2010-2305

LAST UPDATE DATE

2025-04-11T22:56:38.518000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-44910date:2017-08-17T00:00:00
db:BIDid:40960date:2010-06-11T00:00:00
db:JVNDBid:JVNDB-2010-005531date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-201006-271date:2010-06-21T00:00:00
db:NVDid:CVE-2010-2305date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-44910date:2010-06-16T00:00:00
db:BIDid:40960date:2010-06-11T00:00:00
db:JVNDBid:JVNDB-2010-005531date:2012-12-20T00:00:00
db:CNNVDid:CNNVD-201006-271date:2010-06-18T00:00:00
db:NVDid:CVE-2010-2305date:2010-06-16T20:30:02.637