Release date:
Updated on:
Affected Systems:
Symantec Endpoint Protection 11.0
Unaffected system:
Symantec Endpoint Protection 12.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56399
Cve id: CVE-2012-4953
Symantec is an Internet security technology vendor headquartered in cubitino, California.
Symantec Endpoint Protection 11 and Scan Engine 5.2 have a memory corruption vulnerability when processing specially crafted CAB files. You can export system-level permissions to execute arbitrary code.
<* Source: Will Dormann
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Symantec
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.symantec.com/business/security_response/