CVE-2016-5312
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@symantec.com — http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160927_00
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| symantec | messaging_gateway | {"endIncluding":"10.6.1"} | |
References
- http://packetstormsecurity.com/files/138891/Symantec-Messaging-Gateway-10.6.1-Directory-Traversal.html
- http://seclists.org/fulldisclosure/2016/Sep/71
- http://www.securityfocus.com/bid/93148
- http://www.securitytracker.com/id/1036908
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160927_00
- https://www.exploit-db.com/exploits/40437/
- http://packetstormsecurity.com/files/138891/Symantec-Messaging-Gateway-10.6.1-Directory-Traversal.html
- http://seclists.org/fulldisclosure/2016/Sep/71
- http://www.securityfocus.com/bid/93148
- http://www.securitytracker.com/id/1036908
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160927_00
- https://www.exploit-db.com/exploits/40437/
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.