Symantec Content Analysis < 2.3.5.1 affected by Multiple Vulnerabilities (SYMSA1451)

high Nessus Plugin ID 125551
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 5.9

Synopsis

The remote host is running a version of Symantec Content Analysis that is affected by Multiple Vulnerabilities

Description

The version of Symantec Content Analysis running on the remote host is prior to version 2.3.5.1. It is, therefore, affected by multiple vulnerabilities:

- Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
(CVE-2018-7183)

- The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. (CVE-2018-7182)
- ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the 'received' timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp.
(CVE-2018-7184)

Solution

Refer to vendor advisory (Symantec SYMSA1451) for suggested workaround, or upgrade to an unaffected version.

See Also

http://www.nessus.org/u?969586e7

Plugin Details

Severity: High

ID: 125551

File Name: symantec_content_analysis_SYMSA1451.nasl

Version: 1.2

Type: local

Family: Misc.

Published: 5/30/2019

Updated: 6/4/2019

Dependencies: symantec_content_analysis_local_detect.nbin

Risk Information

Risk Factor: High

VPR Score: 5.9

CVSS Score Source: CVE-2018-7183

CVSS v2.0

Base Score: 7.5

Temporal Score: 5.9

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: E:POC/RL:OF/RC:C

CVSS v3.0

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/h:symantec:content_analysis, x-cpe:/h:bluecoat:content_analysis

Required KB Items: installed_sw/Symantec Content Analysis

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/26/2018

Vulnerability Publication Date: 10/11/2018

Reference Information

CVE: CVE-2018-7182, CVE-2018-7183, CVE-2018-7184

BID: 103191, 103192, 103351