CVE-2010-0705

Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:avast:avast_antivirus_home:*:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1169:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1195:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1201:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1227:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1229:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1282:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1290:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1296:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1335:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1351:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_home:4.8.1368.0:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:*:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1169:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1195:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1201:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1227:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1229:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1282:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1290:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1296:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1335:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1351:*:windows:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1356.0:*:*:*:*:*:*:*
cpe:2.3:a:avast:avast_antivirus_professional:4.8.1368.0:*:windows:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:12

Type Values Removed Values Added
References () http://forum.avast.com/index.php?topic=55484.0 - Vendor Advisory () http://forum.avast.com/index.php?topic=55484.0 - Vendor Advisory
References () http://osvdb.org/62510 - () http://osvdb.org/62510 -
References () http://secunia.com/advisories/38677 - Vendor Advisory () http://secunia.com/advisories/38677 - Vendor Advisory
References () http://secunia.com/advisories/38689 - Vendor Advisory () http://secunia.com/advisories/38689 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/509710/100/0/threaded - () http://www.securityfocus.com/archive/1/509710/100/0/threaded -
References () http://www.securityfocus.com/bid/38363 - () http://www.securityfocus.com/bid/38363 -
References () http://www.securitytracker.com/id?1023644 - () http://www.securitytracker.com/id?1023644 -
References () http://www.trapkit.de/advisories/TKADV2010-003.txt - () http://www.trapkit.de/advisories/TKADV2010-003.txt -
References () http://www.vupen.com/english/advisories/2010/0449 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/0449 - Vendor Advisory

Information

Published : 2010-02-25 18:30

Updated : 2024-11-21 01:12


NVD link : CVE-2010-0705

Mitre link : CVE-2010-0705

CVE.ORG link : CVE-2010-0705


JSON object : View

Products Affected

avast

  • avast_antivirus_professional
  • avast_antivirus_home

microsoft

  • windows_xp
  • windows_2000
CWE
CWE-20

Improper Input Validation