CVE-2016-5309
مكوّن محلل ملفات RAR في محرك AntiVirus Decomposer في Symantec Advanced Threat Protection: Network (ATP)؛ وSymantec Email Security.Cloud؛ وSymantec Data...
- تم النشر
- 14/04/2017
- محدث
- 06/08/2024
- تخصيص CNA
- symantec
- الأدلة المرصودة
- 21/09/2016
CVSS الأساسي
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:Hمنخفض · الثلاثين يومًا القادمة
- المئوية
- 93.8%
- تاريخ الموديل
- 21/09/2026
EPSS هو تقدير إحصائي، وليس يقينًا أو مقياسًا للتأثير. ادمجها مع CVSS وحالة KEV والتعرض وبيئتك.
ملخص
مكوّن محلل ملفات RAR في محرك AntiVirus Decomposer في Symantec Advanced Threat Protection: Network (ATP)؛ وSymantec Email Security.Cloud؛ وSymantec Data Center Security: Server؛ وSymantec Endpoint Protection (SEP) لنظام Windows قبل 12.1.6 MP5؛ وSymantec Endpoint Protection (SEP) لنظام Mac؛ وSymantec Endpoint Protection (SEP) لنظام Linux قبل 12.1.6 MP6؛ وSymantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud)؛ وSymantec Endpoint Protection Cloud (SEPC) لنظامي Windows/Mac؛ وSymantec Endpoint Protection Small Business Edition 12.1؛ وCSAPI قبل 10.0.4 HF02؛ وSymantec Protection Engine (SPE) قبل 7.0.5 HF02، و7.5.x قبل 7.5.4 HF02، و7.5.5 قبل 7.5.5 HF01، و7.8.x قبل 7.8.0 HF03؛ وSymantec Mail Security for Domino (SMSDOM) قبل 8.0.9 HF2.1، و8.1.x قبل 8.1.2 HF2.3، و8.1.3 قبل 8.1.3 HF2.2؛ وSymantec Mail Security for Microsoft Exchange (SMSMSE) قبل 6.5.8_3968140 HF2.3، و7.x قبل 7.0_3966002 HF2.1، و7.5.x قبل 7.5_3966008 VHF2.2؛ وSymantec Protection for SharePoint Servers (SPSS) قبل تحديث SPSS_6.0.3_To_6.0.5_HF_2.5، و6.0.6 قبل 6.0.6 HF_2.6، و6.0.7 قبل 6.0.7_HF_2.7؛ وSymantec Messaging Gateway (SMG) قبل 10.6.2؛ وSymantec Messaging Gateway for Service Providers (SMG-SP) قبل 10.5 patch 260 و10.6 قبل patch 259؛ وSymantec Web Gateway؛ وSymantec Web Security.Cloud يسمح للمهاجمين عن بُعد بالتسبب في رفض الخدمة (قراءة خارج الحدود) عبر ملف RAR معدّ بعناية تتم معالجته بشكل غير صحيح أثناء فك الضغط.
المصادر
1- Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Writeاستغلال
Google Security Research · multiple · 21/09/2016
الاستخدام المسؤول
استخدم معلومات الثغرات الأمنية فقط على الأنظمة التي تمتلكها أو المرخص لها باختبارها. يرتبط Kitploit ببيانات تعريف البحث العامة ولا يخزن أكواد الاستغلال أو الحمولات الضارة.