CVE-2016-5309
Die RAR-Datei-Parser-Komponente in der AntiVirus-Decomposer-Engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud;...
- Veröffentlicht
- 14.04.2017
- Aktualisiert
- 06.08.2024
- CNA zuweisen
- symantec
- Beweise beobachtet
- 21.09.2016
Primäres CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HNiedrig · nächste 30 Tage
- Perzentil
- 93,8 %
- Modelldatum
- 21.09.2026
EPSS ist eine statistische Schätzung, keine Gewissheit oder ein Maß für die Auswirkung. Kombinieren Sie es mit CVSS, KEV-Status, Belichtung und Ihrer Umgebung.
Zusammenfassung
Die RAR-Datei-Parser-Komponente in der AntiVirus-Decomposer-Engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows vor 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux vor 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI vor 10.0.4 HF02; Symantec Protection Engine (SPE) vor 7.0.5 HF02, 7.5.x vor 7.5.4 HF02, 7.5.5 vor 7.5.5 HF01 und 7.8.x vor 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) vor 8.0.9 HF2.1, 8.1.x vor 8.1.2 HF2.3 und 8.1.3 vor 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) vor 6.5.8_3968140 HF2.3, 7.x vor 7.0_3966002 HF2.1 und 7.5.x vor 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) vor dem Update SPSS_6.0.3_To_6.0.5_HF_2.5, 6.0.6 vor 6.0.6 HF_2.6 und 6.0.7 vor 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) vor 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) vor 10.5 Patch 260 und 10.6 vor Patch 259; Symantec Web Gateway und Symantec Web Security.Cloud ermöglicht es entfernten Angreifern, einen Denial-of-Service (Out-of-Bounds-Lesen) zu verursachen, indem eine speziell gestaltete RAR-Datei verwendet wird, die während der Dekompression fehlerhaft verarbeitet wird.
Quellen
1Verantwortungsvoller Umgang
Verwenden Sie Schwachstelleninformationen nur auf Systemen, die Sie besitzen oder zu deren Testen Sie berechtigt sind. Kitploit verlinkt auf öffentliche Forschungsmetadaten und speichert keinen Exploit-Code oder bösartige Payloads.