Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

BID:33270

Info

Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

Bugtraq ID: 33270
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jan 14 2009 12:00AM
Updated: Jan 15 2009 04:42PM
Credit: Thierry Zoller
Vulnerable: AVIRA WebGate Suite 0
AVIRA Premium Security Suite 0
AVIRA MailGate Suite 0
AVIRA AntiVir WebGate 0
AVIRA AntiVir Virus Scan Adapter for SAP NetWeaver 0
AVIRA AntiVir SharePoint 0
AVIRA AntiVir Professional 0
AVIRA AntiVir Premium 0
AVIRA AntiVir MIMEsweeper 0
AVIRA AntiVir MailGate 0
AVIRA AntiVir ISA Server 0
AVIRA AntiVir Free 0
AVIRA AntiVir for KEN! 4
AVIRA AntiVir Exchange 0
AVIRA AntiVir Domino 0
Not Vulnerable:

Discussion

Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

Multiple Avira products are prone to a remote denial-of-service vulnerability

An attacker can exploit this issue to crash the affected application, denying service to legitimate users.

The following products are affected; other products may also be affected:

Avira Antivr Free
Avira AntiVir Premium
Avira Premium Security Suite
Avira AntiVir Professional
Avira AntiVir SharePoint
Avira AntiVir Virus Scan Adapter for SAP NetWeaver
Avira AntiVir MailGate
Avira AntiVir Exchange
Avira AntiVir MIMEsweeper
Avira AntiVir Domino
Avira AntiVir WebGate
Avira AntiVir ISA Server
Avira AntiVir for KEN! 4
Avira MailGate Suite
Avira WebGate Suite

Exploit / POC

Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

Solution:
The vendor released fixes to address this issue. Please see the references or contact the vendor for more information.

References

Multiple Avira Products RAR Handling Remote Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report