Description
Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.
Affected products
- F-Secure / f-secure_anti-virus4.50 – 4.50
- Kaspersky Lab / kaspersky_anti-virus5.0.5 – 5.0.5
- Kaspersky Lab / kaspersky_anti-virus5.0.5 – 5.0.5
- Kaspersky Lab / kaspersky_anti-virus_personal5.0.227 – 5.0.227
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/17130
- MISChttp://www.osvdb.org/19913
- MISChttp://www.idefense.com/application/poi/display?id=318&type=vulnerabilities
- MISChttp://www.osvdb.org/19912
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/22564
- MISChttp://www.securityfocus.com/bid/15054
- VENDOR_ADVISORYhttp://secunia.com/advisories/17144