PT-2005-3298 · Avast · Avast Antivirus

Publicado

2005-07-27

·

Atualizado

2008-09-05

·

CVE-2005-2384

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions avast! Antivirus Home/Professional Edition versions 4.6.665 avast! Antivirus Server Edition version 4.6.460
Description A directory traversal issue exists in a third-party compression library, specifically UNACEV2.DLL, used by avast! Antivirus. This issue allows remote attackers to write arbitrary files by using an ACE archive that contains filenames with either .. or absolute pathnames.
Recommendations For avast! Antivirus Home/Professional Edition version 4.6.665, consider updating to a version that does not use the vulnerable UNACEV2.DLL library. For avast! Antivirus Server Edition version 4.6.460, consider updating to a version that does not use the vulnerable UNACEV2.DLL library. As a temporary workaround, consider restricting the handling of ACE archives until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2384

Produtos afetados

Avast Antivirus