Symantec Content Analysis < 2.3.5.1 affected by Multiple Vulnerabilities (SYMSA1463)

high Nessus Plugin ID 125550

Synopsis

The remote host is running a version of Symantec Content Analysis that is affected by Multiple Vulnerabilities

Description

The version of Symantec Content Analysis running on the remote host is prior to version 2.3.5.1. It is, therefore, affected by multiple vulnerabilities:
- An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.
(CVE-2018-1336)

- When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS.(CVE-2018-8019)
- Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses.
(CVE-2018-8020)

- The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. (CVE-2018-8034)

Solution

Refer to vendor advisory (Symantec SYMSA1463) for suggested workaround, or upgrade to an unaffected version.

See Also

https://support.symantec.com/en_US/article.SYMSA1463.html

Plugin Details

Severity: High

ID: 125550

File Name: symantec_content_analysis_SYMSA1463.nasl

Version: 1.2

Type: local

Family: Misc.

Published: 5/30/2019

Updated: 10/30/2019

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2018-8034

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/h:symantec:content_analysis, x-cpe:/h:bluecoat:content_analysis

Required KB Items: installed_sw/Symantec Content Analysis

Exploit Ease: No known exploits are available

Patch Publication Date: 10/11/2018

Vulnerability Publication Date: 7/22/2018

Reference Information

CVE: CVE-2018-1336, CVE-2018-8019, CVE-2018-8020, CVE-2018-8034

BID: 104895, 104898, 104934, 104936