PT-2017-1472 · Intel · Intel Security Virusscan Enterprise Linux
Andrew Fasano
·
Published
2017-03-14
·
Updated
2017-09-03
·
CVE-2016-8020
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Intel Security VirusScan Enterprise Linux (VSEL) versions 2.0.3 and earlier
Description
The issue is related to improper control of code generation, allowing remote authenticated users to execute arbitrary code via a crafted HTTP request parameter. This can also lead to bypassing sandbox mechanisms or causing a denial of service through a specially crafted parameter in an HTTP request.
Recommendations
For versions 2.0.3 and earlier, update to a version later than 2.0.3 to resolve the issue.
As a temporary workaround, consider restricting access to the HTTP request parameter to minimize the risk of exploitation.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Security Virusscan Enterprise Linux