Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability |
|---|---|
| Date: | Thu, 30 Mar 2006 15:53:37 +0300 (EEST) |
Networksecurity.fi Security Advisory (30-03-2006)
Title: McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability Criticality: High (3/3) Affected software: McAfee VirusScan versions 10 Build 10.0.21 and prior Author: Juha-Matti Laurio Date: 30th March, 2006 Advisory ID: Networksecurity.fi Security Advisory (30-03-2006) (#16) CVE reference: CVE-2004-1094
From US-CERT VU#582498:"Impact:
The following products use an affected component: McAfee VirusScan
Vendor and vendor Product Page: McAfee, Inc. http://www.mcafee.com http://us.mcafee.com/root/package.asp?pkgid=100&cid=16269
- Solution: Apply an updated product version or update product via SecurityCenter.
Workarounds: No working workarounds available.
- References: US-CERT VU#582498: "InnerMedia DynaZip library vulnerable to buffer overflow via long file names" http://www.kb.cert.org/vuls/id/582498 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1094
Credit information: This vulnerability was researched by Juha-Matti Laurio, Networksecurity.fi.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] linux routing table ip-lookup algorithm ??, Javor Ninov |
|---|---|
| Next by Date: | [Full-disclosure] Re: ExplorerXP : Directory Traversal and Cross SiteScripting, Dave Korn |
| Previous by Thread: | [Full-disclosure] Fwd: On sandboxes, and why I ... don't care., michaelslists |
| Next by Thread: | [Full-disclosure] Re: Strange interactions between tunnelling and SMB under the proprietary Microsoft Windows environment, Jay Libove |
| Indexes: | [Date] [Thread] [Top] [All Lists] |