4.3
CVSSv2

CVE-2016-5309

Published: 14/04/2017 Updated: 09/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows prior to 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux prior to 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI prior to 10.0.4 HF02; Symantec Protection Engine (SPE) prior to 7.0.5 HF02, 7.5.x prior to 7.5.4 HF02, 7.5.5 prior to 7.5.5 HF01, and 7.8.x prior to 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) prior to 8.0.9 HF2.1, 8.1.x prior to 8.1.2 HF2.3, and 8.1.3 prior to 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) prior to 6.5.8_3968140 HF2.3, 7.x prior to 7.0_3966002 HF2.1, and 7.5.x prior to 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 prior to 6.0.6 HF_2.6, and 6.0.7 prior to 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) prior to 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) prior to 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote malicious users to cause a denial of service (out-of-bounds read) via a crafted RAR file that is mishandled during decompression.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom symantec data center security server -

symantec advanced threat protection -

symantec csapi

symantec email security.cloud -

symantec endpoint protection

symantec endpoint protection cloud -

symantec endpoint protection for small business -

symantec endpoint protection for small business

symantec mail security for domino

symantec mail security for domino 8.1.2

symantec mail security for domino 8.1.3

symantec mail security for microsoft exchange

symantec mail security for microsoft exchange 7.0

symantec mail security for microsoft exchange 7.0.1

symantec mail security for microsoft exchange 7.0.2

symantec mail security for microsoft exchange 7.0.3

symantec mail security for microsoft exchange 7.0.4

symantec mail security for microsoft exchange 7.5

symantec mail security for microsoft exchange 7.5.1

symantec mail security for microsoft exchange 7.5.2

symantec mail security for microsoft exchange 7.5.3

symantec mail security for microsoft exchange 7.5.4

symantec messaging gateway

symantec messaging gateway for service providers 10.5

symantec messaging gateway for service providers 10.6

symantec protection engine

symantec protection engine 7.5.0

symantec protection engine 7.5.1

symantec protection engine 7.5.2

symantec protection engine 7.5.3

symantec protection engine 7.5.4

symantec protection engine 7.5.5

symantec protection engine 7.8.0

symantec protection for sharepoint servers 6.0.3

symantec protection for sharepoint servers 6.0.4

symantec protection for sharepoint servers 6.0.5

symantec protection for sharepoint servers 6.0.6

symantec protection for sharepoint servers 6.0.7

symantec web gateway -

symantec web security.cloud -

Exploits

Source: bugschromiumorg/p/project-zero/issues/detail?id=867 In issue 810 we pointed out to Symantec that they hadn't updated their unrar based unpacker for years, and it was vulnerable to dozens of publicly documented flaws I had expected Symantec to rebase on 542 (the latest version as of this writing), but they appear to have just ...