Google security researcher Tavis Ormandy discovered the issues and reported them to the antivirus maker. Both are exploitable via malicious RAR files.
Bugs are easy to weaponize
Most security software these days includes support for scanning files in transit or that arrive on the user's PC. This includes the ability to sniff archived content, may it be in RAR, ZIP, or other archive software.
All security software will unpack the archive and analyze the files found inside. If the RAR file contains malicious code inside its header, it can cause Symantec's software to crash due to an out-of-bounds read error (CVE-2016-5309) or memory corruption (CVE-2016-5310).
"This may cause an application-level denial of service condition but does not allow ...
SOCIAL SHARE CARD GENERATOR