CVE Database
/

CVE-2012-4953

Back to search

CVE-2012-4953

Published: Nov 14, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#985625
third-party-advisory
x_refsource_CERT-VN
1027726
vdb-entry
x_refsource_SECTRACK
56399
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now