This document lists the new fixes and component versions in Symantec Endpoint Protection (SEP) 12.1 Release Update 6 Maintenance Pack 5 (12.1.6 MP5). This information supplements the information found in the Release Notes.
In addition to the following fixes, this release addresses the following security advisories:
FIX ID: 3784668
Symptom: Some messages received by Syslog Server from Symantec Endpoint Protection Manager are not being separated correctly. This occurs because Symantec Endpoint Protection Manager uses \r for an end-of-line character escape when forwarding to a Syslog Server, and the industry standard is \n.
Solution: The management console now provides a dropdown list so that you can select the end-of-line separator when using TCP mode to send logs to Syslog Server.
FIX ID: 3816728
Symptom: For an IPS exclusion, when using a subnet exclusion like 10.13.10.210 with netmask 255.255.255.255, the exclusion fails. All of the exclusion entries that follow fail as well.
Solution: Using netmask 255.255.255.255 no longer causes an IPS exclusion failure.
FIX ID: 3819417
Symptom: The Citrix VDI client computer hangs randomly due to a crash of the process conhost.exe.
Solution: Upgraded the Symantec Endpoint Protection client with SymEFA 6.0.2 to solve these deadlock issues.
FIX ID: 3827790
Symptom: The Linux client for Symantec Endpoint Protection fails to register to the management console. The attempt returns the HTTP error code 400.
Solution: Increased the size of the allowable client registration data, which can also now be configured through the registry key:
FIX ID: 3840898
Symptom: In the client view in Symantec Endpoint Protection Manager, the IPS definitions display as “Not Available”. However, when viewing individual client information, the definitions are actually correct and up-to-date.
Solution: Changed the query to only request the client IPS-related revisions on the displayed list of clients.
FIX ID: 3864196
Symptom: An intermittent but frequent ccSvcHst.exe crash indicates memory heap corruption.
Solution: Updated LiveUpdate Engine from a version that caused this side effect to one that resolves the issue (2.4).
FIX ID: 3865630
Symptom: After an upgrade to Symantec Endpoint Protection 12.1.5 from 12.1.2, scheduled scans take a very long time. Debug logging references the message “User is not Idle.” No user is logged on at the time of the scan.
Solution: Updated the Common Client component.
FIX ID: 3869840
Symptom: Auto-Protect method for detecting attempts to write to file fails on computers that run CentOS 7.1.
Solution: Auto-Protect now interacts correctly in the filesystem’s namespace, allowing these calls to complete successfully.
FIX ID: 3890083
Symptom: In Symantec Endpoint Protection Manager exported risk logs, the event date is later than the event end date.
Solution: Modified the logic to modify the event end date instead of the event date.
FIX ID: 3895213
Symptom: The policy serial number contains a locally formatted time stamp, which causes the policy to display the local time zone instead of GMT for those groups in the management console.
Solution: Displays the GMT time stamp for the policy where it should.
FIX ID: 3904878
Symptom: Group Update Providers running Windows Server 2012 fail to update clients, because the clients are not able to download definitions from them. Group Update Providers running Windows Server 2003 do not experience this issue.
Solution: Added the process ccSvcHst.exe as an exception to Microsoft's firewall rules.
FIX ID: 3917002
Symptom: During an upgrade, Symantec Endpoint Protection removes a service called CCProxy from a third-party product, due to a shared name with a service from an older unsupported Symantec product. The removal of this service causes the application that uses it to fail.
Solution: Modified the code that removed this service.
FIX ID: 3922331
Symptom: On the Symantec Endpoint Protection client for Linux, the process smcd crashes with a segmentation fault in libpthread if the client receives two "Update Now" commands at the same time.
Solution: Modified the code so that it now correctly handles receiving two "Update Now" commands received at the same time. One command is rejected as a duplicate. The other command proceeds as expected.
FIX ID: 3941776
Symptom: SEP client does not start due to it crashing during startup with an invalid read in ccSvcHst.exe, module oleaut32.dll.
Solution: Modified the code so that it correctly handles the crash and leak.
FIX ID: 3809513
Symptom: After an upgrade to 12.1.6, the Symantec Endpoint Protection client does not start due to a SymEFA crash.
Solution: Fixed the code that was not executing properly.
FIX ID: 3813616
Symptom: Any single risk event is logged with a recommendation of running Power Eraser regardless of whether or not it was actually required. No Power Eraser notifications are being triggered.
Solution: Single risk events are no longer flagged as requiring Power Eraser.
FIX ID: 3885749
Symptom: Upgrades initiated through AutoUpgrade fail, even though the installed version is older and should be upgraded. This failure occurs because multiple Symantec Endpoint Protection product codes are found in the Windows Registry, under Installer\UpgradeCodes.
Solution: AutoUpgrade now uses information from the most recent product code set.
FIX ID: 3839455
Symptom: In the Full Definitions Request report viewable in Symantec Endpoint Protection Manager, clients that run versions 12.1.4 – 12.1.6 list Reason Code 8, “Client did not support XDelta,” as to why full content was provided. These client versions support XDelta.
Solution: In this situation, Reason Code 8 indicates that the server sends the full set of definitions due to a failure to send the delta.
FIX ID: 3910719
Symptom: Symantec Endpoint Protection Auto-Protect kernel modules do not compile on Ubuntu 16.04.
Solution: Auto-Protect now successfully compiles and loads on Ubuntu 16.04.
FIX ID: 3793209
Symptom: A Symantec Endpoint Protection client for Linux that does not have a default IP address does not register to the management console that shares the same default gateway in the network.
Solution: Linux client now validates the default gateway IP before using it. If the value is null, it assigns 0.0.0.0 instead.
FIX ID: 3906089
Symptom: Symantec Endpoint Protection client for Linux does not work on Ubuntu 14.04 with kernel version 4.2 because the filename structure of the kernel changed.
Solution: Accounted for changes in 4.2 kernel to allow Auto-Protect to compile, load, and protect.
FIX ID: 3847456
Symptom: Upgrading the Symantec Endpoint Protection client from 12.1.4 to 12.1.6 on Hyper-V cluster servers causes continuous BSODs.
Solution: No longer calls certain SymEFA APIs when dealing with Cluster Shared Volumes (CSV) or network volumes.
FIX ID: 3864271
Symptom: An HTTP 400 error occurs when the Symantec Endpoint Protection client for Linux tries to connect and register with Symantec Endpoint Protection Manager.
Solution: Corrected the limit of the client’s registration data file size. This change allows clients with data files greater than 4MB to successfully connect and register.
FIX ID: 3908313
Symptom: Windows Server 2008 hangs, and the memory dump points to an issue with SRTSP64.sys in fltmgrFltAcquirePushLockExclusive.
Solution: For Auto-Protect, introduced a locking hierarchy among the threads, which does not hold more than one lock at a time (nested exclusive locks).
FIX ID: 3911039
Symptom: On a clustered server configuration, computers experience a BSOD with a stop code of USER_MODE_HEALTH_MONITOR (9e).
Solution: Changed Auto-Protect to properly handle work items to prevent the BSOD.
FIX ID: 3916567
Symptom: The server becomes unusable and unresponsive shortly after an upgrade to 12.1 RU6 MP1a.
Solution: Resolved issue within the DNS Cache component of the SymNetS driver, so that it only tracks Symantec Endpoint Protection client DNS resolutions, instead of all server DNS resolutions.
Red text indicates components that have updated for this release.
An asterisk (*) indicates the component version that is included with the release, but might be updated by LiveUpdate when a newer version is released.
Component |
Version |
AV Engine |
20151.1.1.4* |
Auto-Protect |
14.6.5.7 |
BASH Defs |
10.1.0.96* |
BASH Framework |
8.0.0.137 |
CC |
12.12.1.15 |
CIDS Defs |
15.0.5.10* |
CIDS Framework |
12.4.0.11 |
ConMan |
2.1.1.11 |
D2D |
1.2.0.3 |
D2D_13 |
1.3.0.3 |
DecABI |
2.3.4.3 |
DefUtils |
4.8.1.4 |
DuLuCallback |
1.5.1.5 |
ECOM |
151.1.0.15 |
ERASER |
115.2.1.18* |
IRON |
4.0.6.22 |
LiveUpdate |
2.3.2.7 |
MicroDefs |
3.8.1.1 |
SIS |
91.12.290.5000 |
SymDS |
3.0.0.69 |
SymEFA |
5.2.1.7 |
SymELAM |
1.0.3.17 |
SymEvent |
12.9.6.19 |
SymNetDrv |
14.0.5.2 |
SymVT |
5.4.0.49 |
WLU (Symantec Endpoint Protection Manager) |
3.3.100.15 |