CVE
- Id
- 3929
- CVE No.
- CVE-2001-1125
- Status
- Candidate
- Description
- Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
- Phase
- Proposed (20020315)
- Votes
- ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall
- Comments
- Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split