PT-2006-6603 · Grisoft · Avg Anti-Virus

Sergio Alvarez

·

Published

2006-11-16

·

Updated

2016-11-18

·

CVE-2006-5937

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grisoft AVG Anti-Virus versions prior to 7.1.407
Description The issue is related to multiple integer overflows that can be triggered by crafted archives, specifically CAB or RAR archives, leading to a heap-based buffer overflow. This can allow remote attackers to execute arbitrary code.
Recommendations For versions prior to 7.1.407, update to version 7.1.407 or later to resolve the issue. As a temporary workaround, consider avoiding the use of CAB or RAR archives until the update is applied. Restrict access to the archive handling module to minimize the risk of exploitation.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-5937

Affected Products

Avg Anti-Virus