CVE-2016-5310

MEDIUMCVSS 5.5/10EPSS 5.31%

Last modified

CVE-2016-5310 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (memory corruption) via a crafted RAR file that is mishandled during decompression.. EPSS estimates a 5.31% chance of exploitation in the next 30 days.

Description

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (memory corruption) via a crafted RAR file that is mishandled during decompression.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
5.31%

91.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BroadcomSymantec Data Center Security ServerAll versions
SymantecAdvanced Threat ProtectionAll versions
SymantecCsapi<= 10.0.4
SymantecEmail Security.CloudAll versions
SymantecEndpoint Protection<= 12.1.4
SymantecEndpoint Protection<= 12.1.6
SymantecEndpoint Protection CloudAll versions
SymantecEndpoint Protection For Small Business<= 12.1
SymantecEndpoint Protection For Small BusinessAll versions
SymantecMail Security For Domino<= 8.0.9
SymantecMail Security For Domino8.1.2
SymantecMail Security For Domino8.1.3
SymantecMail Security For Microsoft Exchange<= 6.5.8
SymantecMail Security For Microsoft Exchange7.0
SymantecMail Security For Microsoft Exchange7.0.1
SymantecMail Security For Microsoft Exchange7.0.2
SymantecMail Security For Microsoft Exchange7.0.3
SymantecMail Security For Microsoft Exchange7.0.4
SymantecMail Security For Microsoft Exchange7.5
SymantecMail Security For Microsoft Exchange7.5.1
SymantecMail Security For Microsoft Exchange7.5.2
SymantecMail Security For Microsoft Exchange7.5.3
SymantecMail Security For Microsoft Exchange7.5.4
SymantecMessaging Gateway<= 10.6.1
SymantecMessaging Gateway For Service Providers10.5
SymantecMessaging Gateway For Service Providers10.6
SymantecProtection Engine<= 7.0.5
SymantecProtection Engine7.5.0
SymantecProtection Engine7.5.1
SymantecProtection Engine7.5.2
SymantecProtection Engine7.5.3
SymantecProtection Engine7.5.4
SymantecProtection Engine7.5.5
SymantecProtection Engine7.8.0
SymantecProtection For Sharepoint Servers6.0.3
SymantecProtection For Sharepoint Servers6.0.4
SymantecProtection For Sharepoint Servers6.0.5
SymantecProtection For Sharepoint Servers6.0.6
SymantecProtection For Sharepoint Servers6.0.7
SymantecWeb GatewayAll versions
SymantecWeb Security.CloudAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-5310?
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (memory corruption) via a crafted RAR file that is mishandled during decompression.
How severe is CVE-2016-5310?
CVE-2016-5310 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 5.31% probability of exploitation in the next 30 days.
How do I fix CVE-2016-5310?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-5310?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST