PT-2006-6603 · Grisoft · Avg Anti-Virus

Sergio Alvarez

·

Publicado

2006-11-16

·

Atualizado

2016-11-18

·

CVE-2006-5937

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grisoft AVG Anti-Virus versions prior to 7.1.407
Description The issue is related to multiple integer overflows that can be triggered by crafted archives, specifically CAB or RAR archives, leading to a heap-based buffer overflow. This can allow remote attackers to execute arbitrary code.
Recommendations For versions prior to 7.1.407, update to version 7.1.407 or later to resolve the issue. As a temporary workaround, consider avoiding the use of CAB or RAR archives until the update is applied. Restrict access to the archive handling module to minimize the risk of exploitation.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-5937

Produtos afetados

Avg Anti-Virus