Advisories Blog | G5 Cyber Security

secunia-Ahnlab-2.txt

Secunia Research has discovered a vulnerability in AhnLab V3 Antivirus, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error in the archive decompression library when reading the filename of a compressed file from an ALZ, UUE or XXE archive. This can be exploited to cause a stack-based buffer overflow (ALZ), or a heap-based buffer overflow (UUE/XXE), when a malicious ALZ/UUE/XXE archive is scanned. Successful exploitation allows arbitrary code execution, but requires that compressed file scanning is enabled.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/40727/secunia-Ahnlab-2.txt

Source: https://packetstormsecurity.com/files/40727/secunia-Ahnlab-2.txt.html

Exit mobile version