Overview | Issues | Affected Products | Best Practices | Acknowledgements | Revisions
Symantec has released an update to address two issues in the RAR file parser component of the antivirus decomposer engine used by multiple Symantec products.
Parsing of maliciously formatted RAR container files may cause an application-level denial of service condition.
Highest severity issue: Medium
Number of issues: 2
This update applies to the following issues:
TITLE |
CVE |
SEVERITY |
|
CVE-2016-5310 |
Medium |
|
|
CVE-2016-5309 |
Medium |
Symantec has verified the issues and addressed them in product updates as outlined below.
All Norton Security and Norton Antivirus products for Windows and Mac have been updated automatically through LiveUpdate.
The following Symantec enterprise products are affected.
PRODUCT |
SOLUTION |
|
Advanced Threat Protection: Network (ATP) |
Automatically updated via LiveUpdate |
|
Email Security.Cloud |
Automatically updated via LiveUpdate |
|
Symantec Data Center Security: Server (DCS:S) |
Automatically updated via LiveUpdate |
|
Symantec Endpoint Protection (SEP) |
12.1.6 MP5: Automatically updated via LiveUpdate
|
|
Symantec Endpoint Protection (SEP) |
Automatically updated via LiveUpdate Apply definitions dated September 17th, 2016 rev. 1 or later. Engine Version: 12.1.4 r11
|
|
Symantec Endpoint Protection (SEP) |
Apply 12.1.6 MP6 update, reboot required |
|
Symantec Endpoint Protection |
Workstations: Automatically updated via LiveUpdate, reboot may be required
|
|
Symantec Endpoint Protection |
Automatically updated via LiveUpdate |
|
Symantec Endpoint Protection |
Follow instructions in support article |
|
CSAPI |
Apply 10.0.4 HF02 update |
|
Symantec Protection Engine (SPE)
|
7.8.0: Apply 7.8.0 HF03 update 7.5.5 and prior: Apply 7.5.5 HF01 update 7.5.4 (AWS): Apply 7.5.4 HF02 update 7.0.5 and prior: Apply SPE 7.0.5 HF02 update
|
|
Symantec Mail Security
|
8.1.3: Apply SMSDOM_8.1.3_HF2.2 update 8.1.2: Apply SMSDOM_8.1.2_HF2.3 update 8.0.9 and prior: Apply SMSDOM_8.0.9_HF2.1 update
|
|
Symantec Mail Security
|
7.5.4 and prior: Apply SMSMSE_7.5_3966008_VHF2.2 update 7.0.4 and prior: Apply SMSMSE_7.0_3966002_HF2.1 update 6.5.8: Apply SMSMSE_6.5.8_3968140_HF2.3 update
|
|
Symantec Protection
|
6.0.7: Apply SPSS_6.0.7_HF_2.7 update
6.0.6: Apply SPSS_6.0.6_HF_2.6 update
|
|
Symantec Messaging Gateway (SMG) |
Apply SMG 10.6.2 update |
|
Symantec Messaging Gateway |
10.6: Apply SMG-SP 10.6 patch 259 update 10.5: Apply SMG-SP 10.5 patch 260 update |
|
Symantec Web Gateway |
Automatically updated via LiveUpdate |
|
Symantec Web Security.Cloud |
Automatically updated via LiveUpdate |
CVE-2016-5310
BID: 92866
Severity: Medium (CVSSv3: 6.9) - AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Impact: Denial of service
Exploitation: None
Date patched: September 19, 2016
Parsing of maliciously formatted RAR container files may cause memory corruption. This may cause an application-level denial of service condition but does not allow any additional exploit opportunities.
CVE-2016-5309
BID: 92868
Severity: Medium (CVSSv3: 4.8) - AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Impact: Denial of service
Exploitation: None
Date patched: September 19, 2016
Parsing of maliciously formatted RAR container files may cause an out-of-bounds (OOB) read error. This may cause an application-level denial of service condition but does not allow any additional exploit opportunities.
Symantec recommends the following measures to reduce risk of attack:
Tavis Ormandy of Google Project Zero (CVE-2016-5309, CVE-2016-5310)
9/19/2016 – Added additional information to SEP for Mac in affected product table regarding updates