CVE-2016-5310
يسمح مكوّن محلل ملفات RAR في محرك AntiVirus Decomposer في كلٍّ من: Symantec Advanced Threat Protection: Network (ATP)؛ وSymantec Email Security.Cloud؛...
- تم النشر
- 14/04/2017
- محدث
- 06/08/2024
- تخصيص CNA
- symantec
- الأدلة المرصودة
- 21/09/2016
CVSS الأساسي
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:Hمنخفض · الثلاثين يومًا القادمة
- المئوية
- 92.3%
- تاريخ الموديل
- 21/09/2026
EPSS هو تقدير إحصائي، وليس يقينًا أو مقياسًا للتأثير. ادمجها مع CVSS وحالة KEV والتعرض وبيئتك.
ملخص
يسمح مكوّن محلل ملفات RAR في محرك AntiVirus Decomposer في كلٍّ من: Symantec Advanced Threat Protection: Network (ATP)؛ وSymantec Email Security.Cloud؛ وSymantec Data Center Security: Server؛ وSymantec Endpoint Protection (SEP) لنظام Windows قبل 12.1.6 MP5؛ وSymantec Endpoint Protection (SEP) لنظام Mac؛ وSymantec Endpoint Protection (SEP) لنظام Linux قبل 12.1.6 MP6؛ وSymantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud)؛ وSymantec Endpoint Protection Cloud (SEPC) لأنظمة Windows/Mac؛ وSymantec Endpoint Protection Small Business Edition 12.1؛ وCSAPI قبل 10.0.4 HF02؛ وSymantec Protection Engine (SPE) قبل 7.0.5 HF02، و7.5.x قبل 7.5.4 HF02، و7.5.5 قبل 7.5.5 HF01، و7.8.x قبل 7.8.0 HF03؛ وSymantec Mail Security for Domino (SMSDOM) قبل 8.0.9 HF2.1، و8.1.x قبل 8.1.2 HF2.3، و8.1.3 قبل 8.1.3 HF2.2؛ وSymantec Mail Security for Microsoft Exchange (SMSMSE) قبل 6.5.8_3968140 HF2.3، و7.x قبل 7.0_3966002 HF2.1، و7.5.x قبل 7.5_3966008 VHF2.2؛ وSymantec Protection for SharePoint Servers (SPSS) قبل تحديث SPSS_6.0.3_To_6.0.5_HF_2.5، و6.0.6 قبل 6.0.6 HF_2.6، و6.0.7 قبل 6.0.7_HF_2.7؛ وSymantec Messaging Gateway (SMG) قبل 10.6.2؛ وSymantec Messaging Gateway for Service Providers (SMG-SP) قبل 10.5 patch 260 و10.6 قبل patch 259؛ وSymantec Web Gateway؛ وSymantec Web Security.Cloud للمهاجمين عن بُعد بالتسبب في رفض الخدمة (تلف في الذاكرة) عبر ملف RAR مُعدّ بعناية يُساء التعامل معه أثناء فك الضغط.
المصادر
1- Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Writeاستغلال
Google Security Research · multiple · 21/09/2016
الاستخدام المسؤول
استخدم معلومات الثغرات الأمنية فقط على الأنظمة التي تمتلكها أو المرخص لها باختبارها. يرتبط Kitploit ببيانات تعريف البحث العامة ولا يخزن أكواد الاستغلال أو الحمولات الضارة.