Description: Sergio Alvarez has reported two vulnerabilities in avast!, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerabilities are caused due to errors within the parsing of .CAB and .SIS files and can be exploited to cause heap-based buffer overflows via a specially crafted .CAB or .SIS file.
Successful exploitation may allow execution of arbitrary code.
The vulnerabilities reportedly affects versions prior to 4.7.766 for servers, 4.7.700 for the Managed Client product, and 4.7.1029 for Home/Professional editions.
Provided and/or discovered by: Sergio Alvarez, n.runs AG
Changelog: 2007-05-25: Added additional vulnerable file type and links.
2007-05-29: Added link to US-CERT.
2007-06-01: Added CVE reference.
2007-07-30: Added Home/Professional edition in list of affected products. Added additional vendor link.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.