Risk: High
A buffer overflaw flaw has been discovered in Norton's Personal Firewall, which could be exploited by malicious people to compromise a user's system.
The vulnerability is caused by a boundary error in the ISAlertDataCOM ActiveX control (ISLAlert.dll) when handling the "Set()" and "Get()" methods. It can be exploited to cause a stack-based buffer overflow via an overly long argument and can allow execution of arbitrary code.
Applying product updates by LiveUpdate, Norton's daily update service, combats the problem.