PT-2006-5411 · Alwil · Avast! Anti-Virus Engine
Published
2006-09-07
·
Updated
2011-03-08
·
CVE-2006-4626
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
alwil avast! Anti-virus Engine versions prior to 4.7.869
Description
The issue is related to a heap-based buffer overflow that can be triggered by a crafted LHA file. This file contains extended headers with file and directory names whose concatenation leads to the overflow, allowing remote attackers to execute arbitrary code.
Recommendations
For versions prior to 4.7.869, update to version 4.7.869 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avast! Anti-Virus Engine