// For flags

CVE-2015-5689

Symantec Ghost Out-Of-Bounds Indexing Remote Code Execution Vulnerability

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image.

Vulnerabilidad en ghostexp.exe en Ghost Explorer Utility en Symantec Ghost Solutions Suite (GSS) en versiones anteriores a 3.0 HF2 12.0.0.8010 y Symantec Deployment Solution (DS) en versiones anteriores a 7.6 HF4 12.0.0.7045, realiza una operación de extensión de signo indebida antes de los accesos a los elementos del array, lo que permite a atacantes remotos ejecutar código arbitrario, causar una denegación de servicio (caída de la aplicación) o posiblemente obtener información sensible a través de una imagen Ghost manipulada.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Symantec Ghost. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of Ghost images. The issue lies in sign-extending byte values from an array before using them as an index into an array, allowing for out-of-bounds access. An attacker can leverage this vulnerability to execute arbitrary code within the context of the current process.

*Credits: Steven Seeley of Source Incite
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-07-28 CVE Reserved
  • 2015-09-03 CVE Published
  • 2024-07-10 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Symantec
Search vendor "Symantec"
Deployment Solution
Search vendor "Symantec" for product "Deployment Solution"
6.9
Search vendor "Symantec" for product "Deployment Solution" and version "6.9"
sp3
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
1.0
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "1.0"
-
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
1.1
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "1.1"
-
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
1.1
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "1.1"
p2
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
2.0
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "2.0"
-
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
2.0.1
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "2.0.1"
-
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
2.0.2
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "2.0.2"
-
Affected
Symantec
Search vendor "Symantec"
Ghost Solutions Suite
Search vendor "Symantec" for product "Ghost Solutions Suite"
2.1
Search vendor "Symantec" for product "Ghost Solutions Suite" and version "2.1"
-
Affected