>> F-Prot Antivirus for UNIX CHM Buffer Overflow and ACE Denial of Service Vulnerabilities
Title : F-Prot Antivirus for UNIX CHM Buffer Overflow and ACE Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2006-4830 CVE ID : CVE-2006-6293 - CVE-2006-6294 - CVE-2006-6352
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-02
Technical Description
Multiple vulnerabilities have benn identified in F-Prot Antivirus for UNIX, which could be exploited by remote attackers to execute arbitrary commands or cause a denial of service.
The first flaw is due to a heap overflow error in the CHM unpacker when handling malformed files, which could be exploited by attackers or malware to compromise a vulnerable system.
The second flaw is due to an error when processing malformed ACE archives, which could be exploited by attackers to crash an affected application.