A vulnerability allows attackers to create a denial of service condition on software with vulnerable installations of the Symantec’s AntiVirus engine. Authentication is not required to exploit this vulnerability. The specific flaw resides in a forged PACK_SIZE field of a RAR file header. By setting this field to a specific value an infinite loop denial of service condition will occur when the scanner processes the file.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57731/ZDI-07-039.txt
Source: https://packetstormsecurity.com/files/57731/Zero-Day-Initiative-Advisory-07-039.html

