|
RESEARCH
Security AdvisoriesAvast antivirus for Linux multiple vulnerabilities.SynopsisMultiple buffer overflows were discovered in the GNU/Linux version of Avast when analyzing corrupted ISO and RPM files.Affected SoftwareAvast for Workstations v1.0.8 Trial versions, possibly others.ImpactRemove DoS, possibly remote code execution.Vendor ResponseOn September 24th 2008, the vendor stated : "With (the) mentioned version of avast4workstation 1.0.8_2, indeed, this bug existed. It was a stack-overflow, caused by cycling over intertwined directories on corrupted ISO files. All versions built since 22.1.2008 have this fixed. Thanks for your report."CreditsThis vulnerability was discovered by Security Researcher Jonathan Brossard from iViZ Techno Solutions Pvt. Ltd.Disclosure Timeline First private disclosure to vendor on September 18th 2008.
|
