7.5

CVE-2006-4626

Exploit
Heap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file that contains extended headers with file and directory names whose concatenation triggers the overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Alwil ≫ Avast Antivirus Edition server Version <= 4.6.460
Alwil ≫ Avast Antivirus Version <= 4.6.763
Alwil ≫ Avast Antivirus Version 4.0.168
Alwil ≫ Avast Antivirus Version 4.0.172
Alwil ≫ Avast Antivirus Version 4.0.183
Alwil ≫ Avast Antivirus Version 4.0.202
Alwil ≫ Avast Antivirus Version 4.0.211
Alwil ≫ Avast Antivirus Version 4.0.229
Alwil ≫ Avast Antivirus Version 4.0.235
Alwil ≫ Avast Antivirus Version 4.1.260
Alwil ≫ Avast Antivirus Version 4.1.268
Alwil ≫ Avast Antivirus Version 4.1.278
Alwil ≫ Avast Antivirus Version 4.1.287
Alwil ≫ Avast Antivirus Version 4.1.289
Alwil ≫ Avast Antivirus Version 4.1.304
Alwil ≫ Avast Antivirus Version 4.1.319
Alwil ≫ Avast Antivirus Version 4.1.335
Alwil ≫ Avast Antivirus Version 4.1.342
Alwil ≫ Avast Antivirus Version 4.1.357
Alwil ≫ Avast Antivirus Version 4.1.389
Alwil ≫ Avast Antivirus Version 4.1.396
Alwil ≫ Avast Antivirus Version 4.1.412
Alwil ≫ Avast Antivirus Version 4.1.418
Alwil ≫ Avast Antivirus Version 4.1.501
Alwil ≫ Avast Antivirus Version 4.5.518
Alwil ≫ Avast Antivirus Version 4.5.549
Alwil ≫ Avast Antivirus Version 4.5.561
Alwil ≫ Avast Antivirus Version 4.6.603
Alwil ≫ Avast Antivirus Version 4.6.623
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.7% 0.909
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/21794
http://www.hustlelabs.com/advisories/04072006_alwil.pdf
Patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/19903
http://www.vupen.com/english/advisories/2006/3515