Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
BID:19903
CVE-2006-4626 |Info
Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
| Bugtraq ID: | 19903 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Sep 08 2006 05:52PM |
| Credit: | Ryan Smith is credited with the discovery of this vulnerability. |
| Vulnerable: |
SmartMax Software MailMax 5.5 SmartMax Software MailMax 5.0.10 .8 SmartMax Software MailMax 5.0.10 .7 SmartMax Software MailMax 5.0.10 .6 SmartMax Software MailMax 5.0 SmartMax Software MailMax 4.8 SmartMax Software MailMax 1.0 Paul Smith Computer Services VPOP3 Email Server 0 NoticeWare Internet Anywhere eMailServer 0 NetWin SurgeMail 3.0 c2 NetWin SurgeMail 3.0 a NetWin SurgeMail 2.2 g3 NetWin SurgeMail 2.2 g2 NetWin SurgeMail 2.2 c9 NetWin SurgeMail 2.2 c10 NetWin SurgeMail 2.2 a6 NetWin SurgeMail 2.1 c7 NetWin SurgeMail 2.1 a NetWin SurgeMail 2.0 g2 NetWin SurgeMail 2.0 e NetWin SurgeMail 2.0 c NetWin SurgeMail 2.0 a2 NetWin SurgeMail 1.9 b2 NetWin SurgeMail 1.9 NetWin SurgeMail 1.8 g3 NetWin SurgeMail 1.8 e NetWin SurgeMail 1.8 d NetWin SurgeMail 1.8 b3 NetWin SurgeMail 1.8 a IceWarp Merak Mail Server 6.1 .0 IceWarp Merak Mail Server 6.0.7 IceWarp Merak Mail Server 5.3.2 IceWarp Merak Mail Server 5.3 .0 IceWarp Merak Mail Server 5.1.3 IceWarp Merak Mail Server 5.1.2 IceWarp Merak Mail Server 4.1 0.050 IceWarp Merak Mail Server 4.1 0.040 IceWarp Merak Mail Server 4.0 0.30 IceWarp Merak Mail Server 3.0 0.100 IceWarp Merak Mail Server 2.1 0.360 IceWarp Merak Mail Server 2.1 0.290 IceWarp Merak Mail Server 2.1 0.280 IceWarp Merak Mail Server 2.1 0.260 IceWarp Merak Mail Server 2.1 0.250 Bains Digital Defender MX 0 Avast Antivirus Server Edition 4.6.489 Avast Antivirus Server Edition 4.6.460 Avast Antivirus Professional Edition 4.7.844 Avast Antivirus Professional Edition 4.7.827 Avast Antivirus Professional Edition 4.6.691 Avast Antivirus Professional Edition 4.6.665 Avast Antivirus Professional Edition 4.6.652 Avast Antivirus Professional Edition 4.6.603 Avast Antivirus Professional Edition 4.6 Avast Antivirus Professional Edition 4.0 Avast Antivirus Home Edition 4.7.844 Avast Antivirus Home Edition 4.7.827 Avast Antivirus Home Edition 4.6.691 Avast Antivirus Home Edition 4.6.691 Avast Antivirus Home Edition 4.6.665 Avast Antivirus Home Edition 4.6.655 Avast Antivirus Home Edition 4.6.652 Avast Antivirus Home Edition 4.6 Avast Antivirus Home Edition 4.0 |
| Not Vulnerable: |
Avast Antivirus Server Edition 4.7.660 Avast Antivirus Home Edition 4.7.869 |
Discussion
Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
Avast! antivirus engine is prone to a buffer-overflow vulnerability in its LHA processing routines.
A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition in the LHA processing engine. This may lead to arbitrary code execution in the context of applications that use the vulnerable engine. This may result in a full computer compromise.
Applications that use versions of Avast! antivirus engine earlier than 4.7.869 (for desktops) or 4.7.660 (for servers) are vulnerable to this issue.
Avast! antivirus engine is prone to a buffer-overflow vulnerability in its LHA processing routines.
A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition in the LHA processing engine. This may lead to arbitrary code execution in the context of applications that use the vulnerable engine. This may result in a full computer compromise.
Applications that use versions of Avast! antivirus engine earlier than 4.7.869 (for desktops) or 4.7.660 (for servers) are vulnerable to this issue.
Exploit / POC
Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
Solution:
The reporter of this issue states that a fix is available from the vendor. Symantec has not verified this. Please contact the vendor for more information on obtaining and applying fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
The reporter of this issue states that a fix is available from the vendor. Symantec has not verified this. Please contact the vendor for more information on obtaining and applying fixes.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Avast! Antivirus Engine Remote LHA Buffer Overflow Vulnerability
References:
References: