Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-16T17:04:41.599Z
Reserved: 2002-03-15T00:00:00
Link: CVE-2001-1125

Updated: 2024-08-08T04:44:07.831Z

Status : Deferred
Published: 2001-10-05T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2001-1125

No data.