>> Avira AntiVir Multiple File Parsing Code Execution and Denial of Service Vulnerabilities
Title : Avira AntiVir Multiple File Parsing Code Execution and Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2007-1971 CVE ID : CVE-2007-2972 - CVE-2007-2973 - CVE-2007-2974
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-05-28
Technical Description
Multiple vulnerabilities have been identified in Avira AntiVir, which could be exploited by attackers or malware to take complete control of an affected system or cause a denial of service.
The first issue is caused by a buffer overflow error when processing malformed LZH archives, which could be exploited by attackers to execute arbitrary commands by tricking a system protected by a vulnerable application to scan a malicious file.
The second vulnerability is due to a division by zero error when handling a malformed UPX file, which could be exploited by attackers to crash a vulnerable application, creating a denial of service condition.
The third issue is caused by an infinite loop when processing malformed TAR archives, which could be exploited by attackers to exhaust all available memory resources, creating a denial of service condition.