AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
BID:14824
Info
AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 14824 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2005 12:00AM |
| Updated: | Sep 14 2005 12:00AM |
| Credit: | Discovery is credited to Tan Chew Keong, Secunia Research. |
| Vulnerable: |
AVIRA Desktop for Windows 1.0 0.00.68 |
| Not Vulnerable: | |
Discussion
AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
AVIRA Desktop for Windows is affected by a remote buffer overflow vulnerability when handling ACE archives.
If the application has been enabled to scan compressed files and proceeds to process a malicious archive, a buffer overflow condition can be triggered. This may lead to memory corruption and potentially facilitate arbitrary code execution.
An attacker may exploit this vulnerability to gain unauthorized remote access in the context of SYSTEM.
Desktop for Windows version 1.00.00.68 running AVPACK32.DLL version 6.31.0.3 is reportedly vulnerable. It is possible that other versions are affected as well.
AVIRA Desktop for Windows is affected by a remote buffer overflow vulnerability when handling ACE archives.
If the application has been enabled to scan compressed files and proceeds to process a malicious archive, a buffer overflow condition can be triggered. This may lead to memory corruption and potentially facilitate arbitrary code execution.
An attacker may exploit this vulnerability to gain unauthorized remote access in the context of SYSTEM.
Desktop for Windows version 1.00.00.68 running AVPACK32.DLL version 6.31.0.3 is reportedly vulnerable. It is possible that other versions are affected as well.
Exploit / POC
AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
Solution:
The vendor has released AVPACK32.DLL version 6.31.1.7 to address this issue. Users are advised to upgrade through the online update functionality of the application.
Solution:
The vendor has released AVPACK32.DLL version 6.31.1.7 to address this issue. Users are advised to upgrade through the online update functionality of the application.
References
AVIRA Desktop for Windows ACE Archive Handling Remote Buffer Overflow Vulnerability
References:
References: