CVE-2015-5689: Buffer Overflow
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5689?
CVE-2015-5689 is classified as a critical vulnerability, allowing remote attackers to execute arbitrary code.
How do I fix CVE-2015-5689?
To fix CVE-2015-5689, update your Symantec Deployment Solution to version 7.6 HF4 or later, and Ghost Solutions Suite to version 3.0 HF2 or later.
Which software versions are affected by CVE-2015-5689?
CVE-2015-5689 affects various versions of Symantec Ghost Solutions Suite prior to 3.0 HF2 and Symantec Deployment Solution prior to 7.6 HF4.
What causes CVE-2015-5689?
CVE-2015-5689 is caused by improper sign-extension operations before array-element accesses in the ghostexp.exe component.
Can I exploit CVE-2015-5689 remotely?
Yes, CVE-2015-5689 can be exploited remotely by an attacker to execute arbitrary code.