CVE-2017-5005: Buffer Overflow
Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LCUNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security Scan (aka Custom Scan) operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5005?
CVE-2017-5005 has a high severity level due to its potential for remote code execution.
How do I fix CVE-2017-5005?
To fix CVE-2017-5005, update Quick Heal products to versions later than 10.1.0.316.
What products are affected by CVE-2017-5005?
CVE-2017-5005 affects Quick Heal Internet Security, Total Security, and AntiVirus Pro versions 10.1.0.316 and earlier.
Can CVE-2017-5005 be exploited remotely?
Yes, CVE-2017-5005 can be exploited remotely by attackers through crafted Mach-O files.
Is there a workaround for CVE-2017-5005?
There are no known effective workarounds for CVE-2017-5005, so updating to the latest version is recommended.