CVE-2016-2207
Le moteur AntiVirus Decomposer dans Symantec Advanced Threat Protection (ATP) ; Symantec Data Center Security:Server (SDCS:S) 6.x à 6.6 MP1 ; Symantec Web...
- Publié
- 30 juin 2016
- Mise à jour
- 5 août 2024
- Attribution de CNA
- symantec
- Preuve observée
- 29 juin 2016
CVSS primaire
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:CModéré · 30 prochains jours
- Percentile
- 97,7 %
- Date du modèle
- 21 sept. 2026
EPSS est une estimation statistique, et non une certitude ou une mesure d'impact. Combinez-le avec CVSS, le statut KEV, l'exposition et votre environnement.
Résumé
Le moteur AntiVirus Decomposer dans Symantec Advanced Threat Protection (ATP) ; Symantec Data Center Security:Server (SDCS:S) 6.x à 6.6 MP1 ; Symantec Web Gateway ; Symantec Endpoint Protection (SEP) avant 12.1 RU6 MP5 ; Symantec Endpoint Protection (SEP) pour Mac ; Symantec Endpoint Protection (SEP) pour Linux avant 12.1 RU6 MP5 ; Symantec Protection Engine (SPE) avant 7.0.5 HF01, 7.5.x avant 7.5.3 HF03, 7.5.4 avant HF01 et 7.8.0 avant HF01 ; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 à 6.0.5 avant 6.0.5 HF 1.5 et 6.0.6 avant HF 1.6 ; Symantec Mail Security for Microsoft Exchange (SMSMSE) avant 7.0_3966002 HF1.1 et 7.5.x avant 7.5_3966008 VHF1.2 ; Symantec Mail Security for Domino (SMSDOM) avant 8.0.9 HF1.1 et 8.1.x avant 8.1.3 HF1.2 ; CSAPI avant 10.0.4 HF01 ; Symantec Message Gateway (SMG) avant 10.6.1-4 ; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 avant le correctif 254 et 10.6 avant le correctif 253 ; Norton AntiVirus, Norton Security, Norton Internet Security et Norton 360 avant NGC 22.7 ; Norton Security pour Mac avant 13.0.2 ; Norton Power Eraser (NPE) avant 5.1 ; et Norton Bootable Removal Tool (NBRT) avant 2016.1 permet à des attaquants distants d'exécuter du code arbitraire ou de provoquer un déni de service (violation d'accès mémoire) via un fichier RAR spécialement conçu qui est mal géré lors de la décompression.
Sources
1Google Security Research · multiple · 29 juin 2016
Utilisation responsable
Utilisez les informations de vulnérabilité uniquement sur les systèmes que vous possédez ou que vous êtes autorisé à tester. Kitploit renvoie aux métadonnées de la recherche publique et ne stocke pas de code d'exploitation ni de charges utiles malveillantes.