SB2016063012 - Integer overflow in TNEF decoder in Symantec Scan Engine



SB2016063012 - Integer overflow in TNEF decoder in Symantec Scan Engine

Published: June 30, 2016 Updated: September 14, 2018

Security Bulletin ID SB2016063012
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Integer overflow in TNEF decoder (CVE-ID: CVE-2016-3645)

The vulnerability does not result in any detrimental actions due to underlying code.

However, the overflow was an exposure due to improper implementation that can potentially be used in the future, at some point, by an attacker.

Remediation

Install update from vendor's website.