CVE-2015-5689

Symantec Ghost Solutions Suite <3.0 HF2 12.0.0.8010 - RCE

Title source: llm
STIX 2.1

Description

ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-15-419/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033577
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76498

Scores

EPSS 0.0300
EPSS Percentile 86.7%

Details

CWE
CWE-119
Status published
Products (7)
symantec/deployment_solution 6.9 sp3
symantec/ghost_solutions_suite 1.0
symantec/ghost_solutions_suite 1.1 (2 CPE variants)
symantec/ghost_solutions_suite 2.0
symantec/ghost_solutions_suite 2.0.1
symantec/ghost_solutions_suite 2.0.2
symantec/ghost_solutions_suite 2.1
Published Sep 20, 2015
Tracked Since Feb 18, 2026