CVE-2016-5309 Details
Description
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1.6 MP6; Symantec Endpoint Protection for Small Business Enterprise (SEP SBE/SEP.Cloud); Symantec Endpoint Protection Cloud (SEPC) for Windows/Mac; Symantec Endpoint Protection Small Business Edition 12.1; CSAPI before 10.0.4 HF02; Symantec Protection Engine (SPE) before 7.0.5 HF02, 7.5.x before 7.5.4 HF02, 7.5.5 before 7.5.5 HF01, and 7.8.x before 7.8.0 HF03; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF2.1, 8.1.x before 8.1.2 HF2.3, and 8.1.3 before 8.1.3 HF2.2; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 6.5.8_3968140 HF2.3, 7.x before 7.0_3966002 HF2.1, and 7.5.x before 7.5_3966008 VHF2.2; Symantec Protection for SharePoint Servers (SPSS) before SPSS_6.0.3_To_6.0.5_HF_2.5 update, 6.0.6 before 6.0.6 HF_2.6, and 6.0.7 before 6.0.7_HF_2.7; Symantec Messaging Gateway (SMG) before 10.6.2; Symantec Messaging Gateway for Service Providers (SMG-SP) before 10.5 patch 260 and 10.6 before patch 259; Symantec Web Gateway; and Symantec Web Security.Cloud allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted RAR file that is mishandled during decompression.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom symantec data center security server | All versions |
CPE
Remediation
| |
| symantec advanced threat protection | All versions |
CPE
Remediation
| |
| symantec csapi | <= 10.0.4 |
CPE
Remediation
| |
| symantec email security.cloud | All versions |
CPE
Remediation
| |
| symantec endpoint protection | <= 12.1.4 <= 12.1.6 |
CPE
Remediation
| |
| symantec endpoint protection cloud | All versions |
CPE
Remediation
| |
| symantec endpoint protection for small business | <= 12.1 |
CPE
Remediation
| |
| symantec mail security for domino | <= 8.0.9 8.1.2 8.1.3 |
CPE
Remediation
| |
| symantec mail security for microsoft exchange | <= 6.5.8 7.0 7.0.1 7.0.2 7.0.3 7.0.4 7.5 7.5.1 7.5.2 7.5.3 7.5.4 |
CPE
Remediation
| |
| symantec messaging gateway | <= 10.6.1 |
CPE
Remediation
| |
| symantec messaging gateway for service providers | 10.5 10.6 |
CPE
Remediation
| |
| symantec protection engine | <= 7.0.5 7.5.0 7.5.1 7.5.2 7.5.3 7.5.4 7.5.5 7.8.0 |
CPE
Remediation
| |
| symantec protection for sharepoint servers | 6.0.3 6.0.4 6.0.5 6.0.6 6.0.7 |
CPE
Remediation
| |
| symantec web gateway | All versions |
CPE
Remediation
| |
| symantec web security.cloud | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 9, 2021 | Reanalysis | [email protected] |
| Apr 25, 2017 | Initial Analysis | [email protected] |