CVE-2016-5309
Symantec Advanced Threat Protection: Network (ATP)、Symantec Email Security.Cloud、Symantec Data Center Security: Server、Windows 向け Symantec Endpoint...
- 公開済み
- 2017/04/14
- 更新済み
- 2024/08/06
- CNA の割り当て
- symantec
- 観察された証拠
- 2016/09/21
プライマリ CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H低 · 今後 30 日間
- パーセンタイル
- 93.8%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
Symantec Advanced Threat Protection: Network (ATP)、Symantec Email Security.Cloud、Symantec Data Center Security: Server、Windows 向け Symantec Endpoint Protection (SEP) 12.1.6 MP5 より前、Mac 向け Symantec Endpoint Protection (SEP)、Linux 向け Symantec Endpoint Protection (SEP) 12.1.6 MP6 より前、Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud)、Windows/Mac 向け Symantec Endpoint Protection Cloud (SEPC)、Symantec Endpoint Protection Small Business Edition 12.1、CSAPI 10.0.4 HF02 より前、Symantec Protection Engine (SPE) 7.0.5 HF02 より前、7.5.x 7.5.4 HF02 より前、7.5.5 7.5.5 HF01 より前、7.8.x 7.8.0 HF03 より前、Symantec Mail Security for Domino (SMSDOM) 8.0.9 HF2.1 より前、8.1.x 8.1.2 HF2.3 より前、8.1.3 8.1.3 HF2.2 より前、Symantec Mail Security for Microsoft Exchange (SMSMSE) 6.5.8_3968140 HF2.3 より前、7.x 7.0_3966002 HF2.1 より前、7.5.x 7.5_3966008 VHF2.2 より前、Symantec Protection for SharePoint Servers (SPSS) SPSS_6.0.3_To_6.0.5_HF_2.5 update より前、6.0.6 6.0.6 HF_2.6 より前、6.0.7 6.0.7_HF_2.7 より前、Symantec Messaging Gateway (SMG) 10.6.2 より前、Symantec Messaging Gateway for Service Providers (SMG-SP) 10.5 patch 260 より前および 10.6 patch 259 より前、Symantec Web Gateway、および Symantec Web Security.Cloud の AntiVirus Decomposer エンジンにおける RAR ファイルパーサーコンポーネントは、解凍中に誤って処理される巧妙に細工された RAR ファイルを介して、リモートの攻撃者がサービス拒否(領域外読み取り)を引き起こすことを可能にします。
ソース
1- Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Writeエクスプロイト
Google Security Research · multiple · 2016/09/21
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。