CVE-2012-4953: Buffer Overflow
The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4953?
CVE-2012-4953 is considered a high severity vulnerability due to its potential to allow remote code execution through improperly handled CAB files.
How do I fix CVE-2012-4953?
To fix CVE-2012-4953, ensure that you upgrade to Symantec Endpoint Protection version 11.0 or later, or update to the latest versions of the affected software.
Which software versions are affected by CVE-2012-4953?
CVE-2012-4953 affects Symantec Endpoint Protection 11.0, Endpoint Protection Small Business Edition 12.0, AntiVirus Corporate Edition 10.x, and Scan Engine versions prior to 5.2.8.
Can CVE-2012-4953 be exploited remotely?
Yes, CVE-2012-4953 can potentially be exploited remotely by an attacker leveraging malicious CAB files.
What type of vulnerability is CVE-2012-4953?
CVE-2012-4953 is a buffer overflow vulnerability that affects the decomposer engine of several Symantec products.