CVE-2012-2976: OS Command Injection
Published Jul 23, 2012
·Updated
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.
Affected Software
4 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Symantec Web Gateway=5.0.3
Event History
Jul 23, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2976?
CVE-2012-2976 is classified as a critical vulnerability allowing remote command execution.
2
How do I fix CVE-2012-2976?
To fix CVE-2012-2976, upgrade the Symantec Web Gateway to version 5.0.3.18 or later.
3
What systems are affected by CVE-2012-2976?
CVE-2012-2976 affects Symantec Web Gateway versions 5.0, 5.0.1, 5.0.2, and 5.0.3.
4
What type of vulnerability is CVE-2012-2976?
CVE-2012-2976 is an injection vulnerability that allows remote attackers to execute arbitrary shell commands.
5
Is CVE-2012-2976 actively being exploited?
There are no known active exploits reported for CVE-2012-2976, but it is advisable to apply the fix as a precaution.