Avast! Home/Professional TAR File Processing Heap Corruption

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.715
Località
Torino
Secunia Advisory: SA27929
Release Date: 2007-12-05
Last Update: 2007-12-06

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software: avast! Home/Professional 4.x

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
A vulnerability has been reported in avast! Home/Professional, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error within the handling of specially crafted TAR files. This can be exploited to corrupt heap memory via certain unspecified TAR fields.

The vulnerability is reported in versions prior to 4.7.1098.

Solution:
Update to version 4.7.1098.

http://www.avast.com/eng/download.html


Bollettino Secunia
 
Indietro
Alto Basso