CVE-2007-3970: Race Condition
Published Jul 25, 2007
·Updated
Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.
Affected Software
2 affected components
Eset Software Nod32 Antivirus<=2.2289
ESET NOD32 Antivirus<2.2289
Remediation
Patch Available
Patch Available
Event History
Jul 25, 2007
CVE Published
05:30 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3970?
CVE-2007-3970 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2007-3970?
To resolve CVE-2007-3970, update ESET NOD32 Antivirus to version 2.2290 or later.
3
What types of attacks can exploit CVE-2007-3970?
CVE-2007-3970 can be exploited via crafted CAB files that trigger heap corruption.
4
What versions of ESET NOD32 Antivirus are affected by CVE-2007-3970?
CVE-2007-3970 affects ESET NOD32 Antivirus versions prior to 2.2289.
5
Is there a workaround for CVE-2007-3970?
There are no known workarounds for CVE-2007-3970, so updating the software is recommended.