PT-2012-5686 · Symantec · Symantec Scan Engine+3

Will Dormann

·

Publicado

2012-11-14

·

Atualizado

2013-03-12

·

CVE-2012-4953

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection versions 11.0 Symantec Endpoint Protection Small Business Edition version 12.0 Symantec AntiVirus Corporate Edition versions 10.x Symantec Scan Engine versions prior to 5.2.8
Description The issue is related to the decomposer engine not properly performing bounds checks of the contents of CAB archives. This can be exploited by remote attackers using a crafted file, potentially leading to a denial of service or the execution of arbitrary code.
Recommendations For Symantec Endpoint Protection version 11.0, update to a version that includes the fix for this issue. For Symantec Endpoint Protection Small Business Edition version 12.0, update to a version that includes the fix for this issue. For Symantec AntiVirus Corporate Edition versions 10.x, update to a version that includes the fix for this issue. For Symantec Scan Engine versions prior to 5.2.8, update to version 5.2.8 or later.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4953

Produtos afetados

Symantec Antivirus Corporate Edition
Symantec Endpoint Protection
Symantec Endpoint Protection Small Business Edition
Symantec Scan Engine