SB2016063012 - Integer overflow in TNEF decoder in Symantec Scan Engine
Published: June 30, 2016 Updated: September 14, 2018
Security Bulletin ID
SB2016063012
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow in TNEF decoder (CVE-ID: CVE-2016-3645)
The vulnerability does not result in any detrimental actions due to underlying code.However, the overflow was an exposure due to improper implementation that can potentially be used in the future, at some point, by an attacker.
Remediation
Install update from vendor's website.