>> AVG Anti-Virus UPX File Processing Denial of Service Vulnerability
Title : AVG Anti-Virus UPX File Processing Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2225 CVE ID : CVE-2008-3373 CWE ID : CWE-369
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-29
Technical Description
A vulnerability has been identified in AVG Anti-Virus, which could be exploited by remote attackers or malware to cause a denial of service. This issue is caused by a divide-by-zero error when processing malformed UPX compressed files, which could be exploited by attackers to crash an affected application via a malicious and specially crafted UPX executable, creating a denial of service condition.