Denial of service in Symantec Endpoint Protection - CVE-2016-5309

 

Denial of service in Symantec Endpoint Protection - CVE-2016-5309

Published: September 21, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU575
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5309
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to cause denial of service on the target application.
The weakness exists due to out-of-bounds memory read error. By using specially crafted RAR file attacker can cause denial of the application service.
Successful exploitation of the vulnerability resuslts in denial of service on the vulnerable application.

Affected software

Symantec Endpoint Protection

How to mitigate CVE-2016-5309

Update to 12.1.6 MP5.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins