Decomposer Engine Vulnerability in Symantec Products
CVE-2012-4953

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
14 November 2012

What is CVE-2012-4953?

The decomposer engine in several Symantec products fails to properly enforce bounds checks of CAB archive contents, exposing the system to potential denial of service through application crashes. This vulnerability may also allow remote attackers to execute arbitrary code by exploiting crafted archive files, thus compromising the security of impacted systems.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.