CVE-2005-2384: Medium severity ALWIL Avast Antivirus vulnerability
Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to write arbitrary files via an ACE archive containing filenames with (1) .. or (2) absolute pathnames.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2384?
CVE-2005-2384 is considered to have a medium severity level due to its ability to allow remote attackers to write arbitrary files.
How do I fix CVE-2005-2384?
To fix CVE-2005-2384, users should upgrade to the latest version of avast! Antivirus that addresses this vulnerability.
What types of systems are affected by CVE-2005-2384?
CVE-2005-2384 affects avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460.
What kind of attack is possible due to CVE-2005-2384?
CVE-2005-2384 allows attackers to execute a directory traversal attack, enabling them to manipulate files on the affected system.
Is there a workaround for CVE-2005-2384?
A temporary workaround for CVE-2005-2384 could be to avoid using ACE archives from untrusted sources until the software is updated.