Symantec Content Analysis < 2.3.5.1 affected by Multiple Vulnerabilities (SYMSA1451)

critical Nessus Plugin ID 125551

Synopsis

The remote host is running a version of Symantec Content Analysis that is affected by Multiple Vulnerabilities

Description

The version of Symantec Content Analysis running on the remote host is prior to version 2.3.5.1. It is, therefore, affected by multiple vulnerabilities:

- Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
(CVE-2018-7183)

- The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. (CVE-2018-7182)
- ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the 'received' timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.
(CVE-2018-7184)

Solution

Refer to vendor advisory (Symantec SYMSA1451) for suggested workaround, or upgrade to an unaffected version.

See Also

http://www.nessus.org/u?969586e7

Plugin Details

Severity: Critical

ID: 125551

File Name: symantec_content_analysis_SYMSA1451.nasl

Version: 1.2

Type: local

Family: Misc.

Published: 5/30/2019

Updated: 6/4/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-7183

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/h:symantec:content_analysis, x-cpe:/h:bluecoat:content_analysis

Required KB Items: installed_sw/Symantec Content Analysis

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/26/2018

Vulnerability Publication Date: 10/11/2018

Reference Information

CVE: CVE-2018-7182, CVE-2018-7183, CVE-2018-7184

BID: 103191, 103192, 103351