PT-2005-3298 · Avast · Avast Antivirus
Publicado
2005-07-27
·
Atualizado
2008-09-05
·
CVE-2005-2384
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
avast! Antivirus Home/Professional Edition versions 4.6.665
avast! Antivirus Server Edition version 4.6.460
Description
A directory traversal issue exists in a third-party compression library, specifically UNACEV2.DLL, used by avast! Antivirus. This issue allows remote attackers to write arbitrary files by using an ACE archive that contains filenames with either .. or absolute pathnames.
Recommendations
For avast! Antivirus Home/Professional Edition version 4.6.665, consider updating to a version that does not use the vulnerable UNACEV2.DLL library.
For avast! Antivirus Server Edition version 4.6.460, consider updating to a version that does not use the vulnerable UNACEV2.DLL library.
As a temporary workaround, consider restricting the handling of ACE archives until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Avast Antivirus