PT-2006-6603 · Grisoft · Avg Anti-Virus
Sergio Alvarez
·
Published
2006-11-16
·
Updated
2016-11-18
·
CVE-2006-5937
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Grisoft AVG Anti-Virus versions prior to 7.1.407
Description
The issue is related to multiple integer overflows that can be triggered by crafted archives, specifically CAB or RAR archives, leading to a heap-based buffer overflow. This can allow remote attackers to execute arbitrary code.
Recommendations
For versions prior to 7.1.407, update to version 7.1.407 or later to resolve the issue. As a temporary workaround, consider avoiding the use of CAB or RAR archives until the update is applied. Restrict access to the archive handling module to minimize the risk of exploitation.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avg Anti-Virus