#VU576 Denial of service in Symantec Endpoint Protection - CVE-2016-5310

 

#VU576 Denial of service in Symantec Endpoint Protection - CVE-2016-5310

Published: September 21, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU576
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-5310
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Symantec Endpoint Protection
Software vendor:
Broadcom

Description

The vulnerability allows a remote user to cause denial of service on the target application.
The weakness exists due to memory corruption error. By using specially crafted RAR file attacker can cause denial of the application service.
Successful exploitation of the vulnerability resuslts in denial of service on the vulnerable application.

Remediation

Update to 12.1.6 MP5.

External links