First published: Sun Jul 02 2017(Updated: )
When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer overflow because a fixed path length is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Antiy Antivirus Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10706 is classified as a high severity vulnerability due to the potential for exploiting a stack-based buffer overflow.
To fix CVE-2017-10706, update the Antiy Antivirus Engine to version 5.0.0.05171547 or later.
CVE-2017-10706 affects systems running versions of Antiy Antivirus Engine prior to 5.0.0.05171547.
A stack-based buffer overflow in CVE-2017-10706 occurs when the Antiy Antivirus Engine processes a specially crafted ZIP archive that exceeds the allocated buffer length.
There are no known effective workarounds for CVE-2017-10706; the recommended action is to apply the software update.