>> ESET NOD32 AntiVirus Pathname Handling Remote Command Execution Vulnerabilities
Title : ESET NOD32 AntiVirus Pathname Handling Remote Command Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2007-1911 CVE ID : CVE-2007-2852
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-22
Technical Description
Two vulnerabilities have been identified in ESET NOD32 AntiVirus, which could be exploited by attackers or malware to cause a denial of service or take complete control of an affected system. These issues are caused by stack overflow errors when handling files with a specially crafted path name, which could be exploited by attackers to execute arbitrary commands by tricking a vulnerable application into scanning a specially crafted file.