PT-2006-6603 · Grisoft · Avg Anti-Virus
Sergio Alvarez
·
Publicado
2006-11-16
·
Atualizado
2016-11-18
·
CVE-2006-5937
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Grisoft AVG Anti-Virus versions prior to 7.1.407
Description
The issue is related to multiple integer overflows that can be triggered by crafted archives, specifically CAB or RAR archives, leading to a heap-based buffer overflow. This can allow remote attackers to execute arbitrary code.
Recommendations
For versions prior to 7.1.407, update to version 7.1.407 or later to resolve the issue. As a temporary workaround, consider avoiding the use of CAB or RAR archives until the update is applied. Restrict access to the archive handling module to minimize the risk of exploitation.
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Avg Anti-Virus