CVE-2016-2210
निम्नलिखित उत्पादों के AntiVirus Decomposer इंजन में Dec2LHA.dll में बफर ओवरफ्लो: Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x...
- प्रकाशित
- 30 जून 2016
- अद्यतन
- 5 अग॰ 2024
- सीएनए असाइन करना
- symantec
- साक्ष्य देखे गए
- 29 जून 2016
प्राथमिक सीवीएसएस
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:Cमध्यम · अगले 30 दिन
- प्रतिशत
- 97.6%
- मॉडल दिनांक
- 21 सित॰ 2026
ईपीएसएस एक सांख्यिकीय अनुमान है, कोई निश्चितता या प्रभाव का माप नहीं। इसे सीवीएसएस, केईवी स्थिति, एक्सपोज़र और अपने वातावरण के साथ मिलाएं।
सारांश
निम्नलिखित उत्पादों के AntiVirus Decomposer इंजन में Dec2LHA.dll में बफर ओवरफ्लो: Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x से 6.6 MP1 तक; Symantec Web Gateway; Symantec Endpoint Protection (SEP) 12.1 RU6 MP5 से पहले; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux 12.1 RU6 MP5 से पहले; Symantec Protection Engine (SPE) 7.0.5 HF01 से पहले, 7.5.x 7.5.3 HF03 से पहले, 7.5.4 HF01 से पहले, और 7.8.0 HF01 से पहले; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 से 6.0.5 तक 6.0.5 HF 1.5 से पहले और 6.0.6 HF 1.6 से पहले; Symantec Mail Security for Microsoft Exchange (SMSMSE) 7.0_3966002 HF1.1 से पहले और 7.5.x 7.5_3966008 VHF1.2 से पहले; Symantec Mail Security for Domino (SMSDOM) 8.0.9 HF1.1 से पहले और 8.1.x 8.1.3 HF1.2 से पहले; CSAPI 10.0.4 HF01 से पहले; Symantec Message Gateway (SMG) 10.6.1-4 से पहले; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 पैच 254 से पहले और 10.6 पैच 253 से पहले; Norton AntiVirus, Norton Security, Norton Internet Security, और Norton 360 NGC 22.7 से पहले; Norton Security for Mac 13.0.2 से पहले; Norton Power Eraser (NPE) 5.1 से पहले; और Norton Bootable Removal Tool (NBRT) 2016.1 से पहले, दूरस्थ हमलावरों को एक विशेष रूप से तैयार की गई फ़ाइल के माध्यम से मनमाना कोड निष्पादित करने की अनुमति देता है।
स्रोत
1Google Security Research · multiple · 29 जून 2016
जिम्मेदारीपूर्ण उपयोग
भेद्यता जानकारी का उपयोग केवल उन प्रणालियों पर करें जिनके मालिक आप हैं या परीक्षण के लिए अधिकृत हैं। किटप्लॉइट सार्वजनिक अनुसंधान मेटाडेटा से लिंक करता है और शोषण कोड या दुर्भावनापूर्ण पेलोड को संग्रहीत नहीं करता है।