Eset Software NOD32 Antivirus Local Buffer Overflow Vulnerability
BID:6803
Info
Eset Software NOD32 Antivirus Local Buffer Overflow Vulnerability
| Bugtraq ID: | 6803 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0062 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 10 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The discovery of this vulnerability has been credited to Knud Erik Højgaard ([email protected]). |
| Vulnerable: |
Eset NOD32 Antivirus 1.0 12 Eset NOD32 Antivirus 1.0 11 |
| Not Vulnerable: |
Eset NOD32 Antivirus 1.0 13 |
Discussion
Eset Software NOD32 Antivirus Local Buffer Overflow Vulnerability
A vulnerability has been discovered in NOD32 for the Unix and Linux operating systems. The problem occurs when scanning a directory path of excessive length. When the malicious path is processed sensitive locations in memory may be corrupted.
An attacker could exploit this issue by creating a malicious directory containing a name of excessive length. This issue can be triggered by coaxing a user to scan the location with NOD32. By exploiting this issue to execute code it is possible run arbitrary commands with the privileges of the user running NOD32.
This issue affects NOD32 versions 1.012 and earlier.
A vulnerability has been discovered in NOD32 for the Unix and Linux operating systems. The problem occurs when scanning a directory path of excessive length. When the malicious path is processed sensitive locations in memory may be corrupted.
An attacker could exploit this issue by creating a malicious directory containing a name of excessive length. This issue can be triggered by coaxing a user to scan the location with NOD32. By exploiting this issue to execute code it is possible run arbitrary commands with the privileges of the user running NOD32.
This issue affects NOD32 versions 1.012 and earlier.
Exploit / POC
Eset Software NOD32 Antivirus Local Buffer Overflow Vulnerability
It has been reported that an exploit has been developed for this issue but has not been made publicly available.
It has been reported that an exploit has been developed for this issue but has not been made publicly available.
Solution / Fix
Eset Software NOD32 Antivirus Local Buffer Overflow Vulnerability
Solution:
The vendor has released NOD32 1.013 which address this issue. Users are advised to upgrade their NOD32 packages as soon as possible.
Eset NOD32 Antivirus 1.0 12
Eset NOD32 Antivirus 1.0 11
Solution:
The vendor has released NOD32 1.013 which address this issue. Users are advised to upgrade their NOD32 packages as soon as possible.
Eset NOD32 Antivirus 1.0 12
-
Eset Software NOD32 1.013
http://www.nod32.com/download/download.htm
Eset NOD32 Antivirus 1.0 11
-
Eset Software NOD32 1.013
http://www.nod32.com/download/download.htm