PT-2016-2315 · Symantec · Symantec Protection For Sharepoint Servers+18

Published

2016-06-30

·

Updated

2021-09-08

·

CVE-2016-2207

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symantec Advanced Threat Protection (ATP) Symantec Data Center Security:Server (SDCS:S) versions 6.x through 6.6 MP1 Symantec Web Gateway Symantec Endpoint Protection (SEP) versions prior to 12.1 RU6 MP5 Symantec Endpoint Protection (SEP) for Mac Symantec Endpoint Protection (SEP) for Linux versions prior to 12.1 RU6 MP5 Symantec Protection Engine (SPE) versions prior to 7.0.5 HF01 Symantec Protection Engine (SPE) versions 7.5.x prior to 7.5.3 HF03 Symantec Protection Engine (SPE) version 7.5.4 before HF01 Symantec Protection Engine (SPE) version 7.8.0 before HF01 Symantec Protection for SharePoint Servers (SPSS) versions 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 Symantec Protection for SharePoint Servers (SPSS) version 6.0.6 before HF 1.6 Symantec Mail Security for Microsoft Exchange (SMSMSE) versions prior to 7.0 3966002 HF1.1 Symantec Mail Security for Microsoft Exchange (SMSMSE) versions 7.5.x before 7.5 3966008 VHF1.2 Symantec Mail Security for Domino (SMSDOM) versions prior to 8.0.9 HF1.1 Symantec Mail Security for Domino (SMSDOM) versions 8.1.x before 8.1.3 HF1.2 CSAPI versions prior to 10.0.4 HF01 Symantec Message Gateway (SMG) versions prior to 10.6.1-4 Symantec Message Gateway for Service Providers (SMG-SP) version 10.5 before patch 254 Symantec Message Gateway for Service Providers (SMG-SP) version 10.6 before patch 253 Norton AntiVirus versions prior to NGC 22.7 Norton Security versions prior to NGC 22.7 Norton Internet Security versions prior to NGC 22.7 Norton 360 versions prior to NGC 22.7 Norton Security for Mac versions prior to 13.0.2 Norton Power Eraser (NPE) versions prior to 5.1 Norton Bootable Removal Tool (NBRT) versions prior to 2016.1
Description The issue is caused by an integer overflow or buffer overflow in the AntiVirus Decomposer engine. This can be exploited by a remote attacker using a specially crafted RAR file, potentially allowing the execution of arbitrary code or causing a denial of service due to a memory access violation.
Recommendations For Symantec Advanced Threat Protection (ATP), update to a version that includes the fix for this issue. For Symantec Data Center Security:Server (SDCS:S) versions 6.x through 6.6 MP1, apply the necessary patches or updates to fix the vulnerability. For Symantec Web Gateway, update to a version that includes the fix for this issue. For Symantec Endpoint Protection (SEP) versions prior to 12.1 RU6 MP5, update to version 12.1 RU6 MP5 or later. For Symantec Endpoint Protection (SEP) for Mac, update to a version that includes the fix for this issue. For Symantec Endpoint Protection (SEP) for Linux versions prior to 12.1 RU6 MP5, update to version 12.1 RU6 MP5 or later. For Symantec Protection Engine (SPE) versions prior to 7.0.5 HF01, update to version 7.0.5 HF01 or later. For Symantec Protection Engine (SPE) versions 7.5.x prior to 7.5.3 HF03, update to version 7.5.3 HF03 or later. For Symantec Protection Engine (SPE) version 7.5.4 before HF01, apply HF01 or later. For Symantec Protection Engine (SPE) version 7.8.0 before HF01, apply HF01 or later. For Symantec Protection for SharePoint Servers (SPSS) versions 6.0.3 through 6.0.5 before 6.0.5 HF 1.5, apply HF 1.5 or later. For Symantec Protection for SharePoint Servers (SPSS) version 6.0.6 before HF 1.6, apply HF 1.6 or later. For Symantec Mail Security for Microsoft Exchange (SMSMSE) versions prior to 7.0 3966002 HF1.1, update to version 7.0 3966002 HF1.1 or later. For Symantec Mail Security for Microsoft Exchange (SMSMSE) versions 7.5.x before 7.5 3966008 VHF1.2, update to version 7.5 3966008 VHF1.2 or later. For Symantec Mail Security for Domino (SMSDOM) versions prior to 8.0.9 HF1.1, update to version 8.0.9 HF1.1 or later. For Symantec Mail Security for Domino (SMSDOM) versions 8.1.x before 8.1.3 HF1.2, update to version 8.1.3 HF1.2 or later. For CSAPI versions prior to 10.0.4 HF01, update to version 10.0.4 HF01 or later. For Symantec Message Gateway (SMG) versions prior to 10.6.1-4, update to version 10.6.1-4 or later. For Symantec Message Gateway for Service Providers (SMG-SP) version 10.5 before patch 254, apply patch 254 or later. For Symantec Message Gateway for Service Providers (SMG-SP) version 10.6 before patch 253, apply patch 253 or later. For Norton AntiVirus versions prior to NGC 22.7, update to NGC 22.7 or later. For Norton Security versions prior to NGC 22.7, update to NGC 22.7 or later. For Norton Internet Security versions prior to NGC 22.7, update to NGC 22.7 or later. For Norton 360 versions prior to NGC 22.7, update to NGC 22.7 or later. For Norton Security for Mac versions prior to 13.0.2, update to version 13.0.2 or later. For Norton Power Eraser (NPE) versions prior to 5.1, update to version 5.1 or later. For Norton Bootable Removal Tool (NBRT) versions prior to 2016.1, update to version 2016.1 or later.

Exploit

Fix

RCE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01704
CVE-2016-2207

Affected Products

Csapi
Norton 360
Norton Antivirus
Norton Bootable Removal Tool
Norton Internet Security
Norton Power Eraser
Norton Security
Norton Security For Mac
Symantec Advanced Threat Protection
Symantec Data Center Security:Server
Symantec Endpoint Protection
Symantec Endpoint Protection Client
Symantec Mail Security For Domino
Symantec Mail Security For Microsoft Exchange
Symantec Messaging Gateway
Symantec Message Gateway For Service Providers
Symantec Protection Engine
Symantec Protection For Sharepoint Servers
Symantec Web Gateway