SB2016063012 - Integer overflow in TNEF decoder in Symantec Scan Engine
Published: June 30, 2016 Updated: September 14, 2018
Security Bulletin ID
SB2016063012
CSH Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow in TNEF decoder (CVE-ID: CVE-2016-3645)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
The vulnerability does not result in any detrimental actions due to underlying code.
However, the overflow was an exposure due to improper implementation that can potentially be used in the future, at some point, by an attacker.
Remediation
Install update from vendor's website.