CVE-2016-5309
Symantec Advanced Threat Protection: Network (ATP)、Symantec Email Security.Cloud、Symantec Data Center Security: Server、Windows 版 Symantec Endpoint...
- 已发布
- 2017年4月14日
- 已更新
- 2024年8月6日
- 分配 CNA
- symantec
- 观察到的证据
- 2016年9月21日
初级CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H低 · 未来 30 天
- 百分位
- 93.8%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
Symantec Advanced Threat Protection: Network (ATP)、Symantec Email Security.Cloud、Symantec Data Center Security: Server、Windows 版 Symantec Endpoint Protection (SEP)(12.1.6 MP5 之前版本)、Mac 版 Symantec Endpoint Protection (SEP)、Linux 版 Symantec Endpoint Protection (SEP)(12.1.6 MP6 之前版本)、Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud)、Windows/Mac 版 Symantec Endpoint Protection Cloud (SEPC)、Symantec Endpoint Protection Small Business Edition 12.1、CSAPI(10.0.4 HF02 之前版本)、Symantec Protection Engine (SPE)(7.0.5 HF02 之前版本、7.5.x(7.5.4 HF02 之前版本)、7.5.5(7.5.5 HF01 之前版本)及 7.8.x(7.8.0 HF03 之前版本))、Symantec Mail Security for Domino (SMSDOM)(8.0.9 HF2.1 之前版本、8.1.x(8.1.2 HF2.3 之前版本)及 8.1.3(8.1.3 HF2.2 之前版本))、Symantec Mail Security for Microsoft Exchange (SMSMSE)(6.5.8_3968140 HF2.3 之前版本、7.x(7.0_3966002 HF2.1 之前版本)及 7.5.x(7.5_3966008 VHF2.2 之前版本))、Symantec Protection for SharePoint Servers (SPSS)(SPSS_6.0.3_To_6.0.5_HF_2.5 更新之前版本、6.0.6(6.0.6 HF_2.6 之前版本)及 6.0.7(6.0.7_HF_2.7 之前版本))、Symantec Messaging Gateway (SMG)(10.6.2 之前版本)、Symantec Messaging Gateway for Service Providers (SMG-SP)(10.5 patch 260 之前版本及 10.6 patch 259 之前版本)、Symantec Web Gateway 及 Symantec Web Security.Cloud 中的 AntiVirus Decomposer 引擎的 RAR 文件解析器组件允许远程攻击者通过特制的 RAR 文件造成拒绝服务(越界读取),该文件在解压缩过程中被错误处理。
来源
1Google Security Research · multiple · 2016年9月21日
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。