CVE-2016-5310
Le composant d'analyse des fichiers RAR du moteur AntiVirus Decomposer dans Symantec Advanced Threat Protection: Network (ATP) ; Symantec Email...
- Publié
- 14 avr. 2017
- Mise à jour
- 6 août 2024
- Attribution de CNA
- symantec
- Preuve observée
- 21 sept. 2016
CVSS primaire
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HFaible · 30 prochains jours
- Percentile
- 92,3 %
- Date du modèle
- 21 sept. 2026
EPSS est une estimation statistique, et non une certitude ou une mesure d'impact. Combinez-le avec CVSS, le statut KEV, l'exposition et votre environnement.
Résumé
Le composant d'analyse des fichiers RAR du moteur AntiVirus Decomposer dans Symantec Advanced Threat Protection: Network (ATP) ; Symantec Email Security.Cloud ; Symantec Data Center Security: Server ; Symantec Endpoint Protection (SEP) pour Windows avant 12.1.6 MP5 ; Symantec Endpoint Protection (SEP) pour Mac ; Symantec Endpoint Protection (SEP) pour Linux avant 12.1.6 MP6 ; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud) ; Symantec Endpoint Protection Cloud (SEPC) pour Windows/Mac ; Symantec Endpoint Protection Small Business Edition 12.1 ; CSAPI avant 10.0.4 HF02 ; Symantec Protection Engine (SPE) avant 7.0.5 HF02, 7.5.x avant 7.5.4 HF02, 7.5.5 avant 7.5.5 HF01 et 7.8.x avant 7.8.0 HF03 ; Symantec Mail Security for Domino (SMSDOM) avant 8.0.9 HF2.1, 8.1.x avant 8.1.2 HF2.3 et 8.1.3 avant 8.1.3 HF2.2 ; Symantec Mail Security for Microsoft Exchange (SMSMSE) avant 6.5.8_3968140 HF2.3, 7.x avant 7.0_3966002 HF2.1 et 7.5.x avant 7.5_3966008 VHF2.2 ; Symantec Protection for SharePoint Servers (SPSS) avant la mise à jour SPSS_6.0.3_To_6.0.5_HF_2.5, 6.0.6 avant 6.0.6 HF_2.6 et 6.0.7 avant 6.0.7_HF_2.7 ; Symantec Messaging Gateway (SMG) avant 10.6.2 ; Symantec Messaging Gateway for Service Providers (SMG-SP) avant 10.5 patch 260 et 10.6 avant patch 259 ; Symantec Web Gateway ; et Symantec Web Security.Cloud permet à des attaquants distants de provoquer un déni de service (corruption de la mémoire) via un fichier RAR spécialement conçu qui est mal géré lors de la décompression.
Sources
1Utilisation responsable
Utilisez les informations de vulnérabilité uniquement sur les systèmes que vous possédez ou que vous êtes autorisé à tester. Kitploit renvoie aux métadonnées de la recherche publique et ne stocke pas de code d'exploitation ni de charges utiles malveillantes.